Skip to content

MZ Automation vulnerabilities

3 CVEs tracked

MZ Automation appears in our reporting in the context of its open-source 'libiec61850' library, an implementation of the IEC 61850 protocol used in electrical substations. The main theme revolves around multiple vulnerabilities discovered in versions up to 1.6.1. Three critical issues are highlighted in the reports: CVE-2026-18582 (a flaw in the Report handler), CVE-2026-19206 (a heap-based buffer overflow in the ASDU element handler), and CVE-2026-19259 (a critical gap in the MMS protocol workflow). Defenders should immediately patch the 'libiec61850' library and monitor network traffic targeting the affected functions, particularly the MMS and Sampled Values handlers.

Azərbaycanca: MZ Automation hesabatlarımızda onun açıq mənbəli 'libiec61850' kitabxanası kontekstində görünür, hansı ki, elektrik yarımstansiyalarında istifadə olunan IEC 61850 protokolunun tətbiqidir. Əsas mövzu kitabxananın 1.6.1-ə qədər olan versiyalarında aşkarlanmış çoxsaylı zəifliklərdir. Hesabatlarda üç kritik zəiflik qeyd olunub: CVE-2026-18582 (Report handler-də qüsur), CVE-2026-19206 (ASDU element handler-də heap-based buffer overflow) və CVE-2026-19259 (MMS protokol iş axınında kritik boşluq). Müdafiəçilər dərhal 'libiec61850' kitabxanasını yamalı və təsirlənmiş funksiyaları (xüsusilə MMS və Sampled Values handler-lərini) hədəf alan şəbəkə trafikini izləməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on MZ Automation: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.