# MZ Automation libIEC61850 IEC 61850 flaws disclosed

Published: 2026-07-23 · Severity: medium · Sectors: manufacturing, energy, transportation
Canonical: https://vorant.io/reports/107d98a6-629f-5cdf-8846-1c62fff2bc85/mz-automation-libiec61850-iec-61850-flaws-disclosed

> Four vulnerabilities in MZ Automation's libIEC61850 library could let network-adjacent attackers crash or execute code on IEC 61850 substation devices, with no known active exploitation.

CISA has published an ICS advisory detailing four vulnerabilities in MZ Automation's libIEC61850 library, an open-source implementation of the IEC 61850 protocol used for substation automation and protection/control functions across critical manufacturing, energy, and transportation sectors worldwide. Affected versions range from v1.0.0 through v1.6.1.

The most severe issue, CVE-2026-49035, is a heap-based buffer overflow in MMS Initiate request handling that has been demonstrated to achieve remote code execution when ASLR is disabled, with memory corruption or denial-of-service possible when ASLR is enabled. CVE-2026-50039 is a stack-based buffer overflow triggerable via a ReadRequest, also risking memory corruption. Two additional NULL pointer dereference flaws (CVE-2026-50103 in the GOOSE/R-GOOSE parser, and CVE-2026-50032 in the MMS Write Named Variable List handler) allow network-adjacent attackers to crash subscribing applications or servers via crafted GOOSE frames or malformed WriteRequests.

CISA states no known public exploitation has been reported at this time. MZ Automation recommends updating to the latest build available on its GitHub repository. Standard ICS defense-in-depth guidance applies: minimize internet exposure of control system devices, isolate ICS networks behind firewalls, and use secured VPNs for remote access.

## Mentioned in this report

- Vulnerabilities: CVE-2026-49035, CVE-2026-50032, CVE-2026-50039, CVE-2026-50103

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/107d98a6-629f-5cdf-8846-1c62fff2bc85/mz-automation-libiec61850-iec-61850-flaws-disclosed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
