https://seclists.org/oss-sec/2026/q3/231: libIEC61850: four MMS/GOOSE memory-safety vulnerabilities, including lab RCE
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
MZ Automation LibIEC61850>=v1.0.0<v1.6.2
CVE-2026-49035 identifies a memory-safety vulnerability in the MMS handling of libIEC61850 that can be exploited for potential remote code execution.
The vulnerability CVE-2026-50039 can be mitigated by upgrading to libIEC61850 version 1.6.2, which includes the necessary fixes.
CVE-2026-50032 poses a risk of memory corruption that could potentially lead to unauthorized access or manipulation of MMS communications in electric substations.
Yes, CVE-2026-50103 has been addressed and a patch is available in the updated version 1.6.2 of libIEC61850.
All versions prior to v1.6.2 of libIEC61850 are affected by CVE-2026-49035, CVE-2026-50039, CVE-2026-50032, and CVE-2026-50103.