Critical Vulnerabilities in MZ Automation libIEC61850

Discover critical vulnerabilities in libIEC61850 allowing RCE and denial of service. Update to the latest version now.

viernes, 24 de julio de 2026 • 2 min read • Q2BSTUDIO Team

Actualiza urgentemente para proteger sistemas críticos

A set of critical vulnerabilities has been recently disclosed affecting the libIEC61850 library by MZ Automation, a tool widely used in electrical substation automation and industrial control systems. These flaws, ranging from stack and heap buffer overflows to null pointer dereferences, expose critical sectors such as manufacturing, energy, and transportation to potential attacks that could compromise the safe operation of infrastructures. The severity lies in the fact that an unauthenticated remote attacker could execute arbitrary code or cause denial of service, impacting essential protection, visibility, and control functions.

The affected versions include libIEC61850 from v1.0.0 to v1.6.1. Among the most notable issues is a stack-based buffer overflow (CVE-2026-50039) with a CVSS v4 score of 8.7, allowing memory corruption via a ReadRequest. A heap-based buffer overflow (CVE-2026-49035) was also identified through a malicious MMS Initiate request, which can lead to remote code execution if ASLR is disabled. Additionally, null pointer dereference vulnerabilities (CVE-2026-50103 and CVE-2026-50032) can cause service crashes when processing malformed GOOSE frames with invalid TLV values or empty lists in MMS writes.

Exposure of these systems to the network, especially when connected to the internet or corporate networks without segmentation, multiplies the risk. It is recommended to apply the updates available on the official GitHub repository immediately and follow defense-in-depth practices: isolate control networks with firewalls, use secure VPNs for remote access, and conduct regular cybersecurity audits. In this context, having the support of software development and security specialists becomes paramount.

At Q2BSTUDIO, as a software development and technology company, we understand the complexity of maintaining secure and efficient industrial environments. Our expertise in custom software allows us to design tailored solutions that incorporate security controls from the design phase, mitigating attack vectors like those affecting libIEC61850. We also offer cybersecurity services including penetration testing and vulnerability analysis for industrial control systems, helping organizations identify and fix flaws before they are exploited.

Innovation also involves adopting cloud technologies. We work with cloud AWS/Azure to deploy resilient infrastructures that, combined with Business Intelligence (Power BI) tools, enable real-time monitoring of critical assets. Furthermore, integrating artificial intelligence and AI agents into automation processes helps predict anomalous behavior and respond proactively to threats. These advances, however, require that underlying libraries like libIEC61850 be updated and free of vulnerabilities.

In summary, the vulnerabilities detected in MZ Automation libIEC61850 highlight the need for continuous cybersecurity management in industrial environments. Immediate updating is the first step, but a comprehensive strategy encompassing custom software development, security assessments, cloud computing, and advanced analytics is key to protecting critical infrastructures of the future. At Q2BSTUDIO, we are ready to accompany companies on this journey, offering robust technical solutions tailored to each operational reality.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.