MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws
CISA advisory ICSA-26-204-06 (2026-07-23) discloses four vulnerabilities in MZ Automation's open-source libIEC61850 (versions 1.0.0 through 1.6.1), a C library implementing the IEC 61850 MMS/GOOSE substation-automation protocols and embedded as an OEM component in energy-sector protection, control and monitoring equipment worldwide (CISA, 2026-07-23). The most severe, CVE-2026-49035 (CWE-122 heap-based buffer overflow, CVSS 3.1 8.1 / CVSS 4.0 9.2), is triggered by a crafted MMS Initiate request with no authentication and no user interaction; CISA states remote code execution has been demonstrated where ASLR is disabled, degrading to memory corruption or denial of service where it is enabled (CISA, 2026-07-23). The three companion flaws are a stack overflow via a crafted ReadRequest (CVE-2026-50039), and two null-pointer-dereference DoS conditions — one in the shared L2 GOOSE/R-GOOSE parser via a malformed TLV (CVE-2026-50103), one in the MMS Write Named Variable List handler via a WriteRequest with an empty listOfData field (CVE-2026-50032). A companion advisory, ICSA-26-204-07, covers the sibling lib60870 library (versions ≤ 2.4.0, implementing IEC 60870-5-104 SCADA telecontrol used in chemical, energy and water/wastewater sectors) with an out-of-bounds-read parser-crash DoS, CVE-2026-16002 (CISA, 2026-07-23). CISA reports no known public exploitation of any of the five.
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.1
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.