What is CVE-2026-66364?
CVE-2026-66364 is a boundary handling flaw in the IEC 61850 GOOSE payload parser triggered by a single unauthenticated Layer 2 multicast frame on the process bus. This can cause a parser overrun when an inner element length exceeds its enclosing length. Immediate network segmentation and vendor patch verification are required.
Azərbaycanca: CVE-2026-66364 IEC 61850 GOOSE mesaj parserində sərhəd yoxlaması zəifliyidir. Process bus şəbəkəsində tək bir autentifikasiyasız Layer 2 multicast çərçivəsi parser-in overrun etməsinə səbəb ola bilər. Dərhal şəbəkə seqmentasiyası tətbiq edilməli və vendor yaması yoxlanmalıdır.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which network protocol and parser type are affected by CVE-2026-66364?
CVE-2026-66364 is a boundary handling flaw in the IEC 61850 GOOSE payload parser.
Is authentication required to exploit this vulnerability?
No, the flaw is triggered by a single unauthenticated Layer 2 multicast frame on the process bus.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.