Out‑of‑Bounds Read Vulnerabilities (CVE‑2026‑61893, CVE‑2026‑63033) in MZ Automation lib60870 Could Crash Industrial Devices
What It Is — Two out‑of‑bounds read bugs were disclosed in MZ Automation’s lib60870 2.4.0. A crafted IEC 60870‑5‑104 I‑frame can cause the library to read past the end of a heap buffer, leading to a crash of any device that uses the library.
Exploitability — No public exploit code has been released, but the CVSS v3 base score is 6.5 (moderate). Successful exploitation is feasible for an attacker who can send malicious IEC 60870‑5‑104 traffic to the target device.
Affected Products — MZ Automation lib60870 version 2.4.0 (open‑source library hosted on GitHub).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The vulnerability maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Demonstrating that you have identified, patched, and documented the fix is essential audit evidence.
- Continuous Evidence – Maintaining a verifiable record of library version updates and test results satisfies the “monitoring and response” criteria auditors now expect for critical‑infrastructure software.
- Enterprise Buyer Expectations – Energy and manufacturing customers increasingly require proof that third‑party components are tracked and remediated in real time as part of SOC 2 readiness.
Recommended Actions
- Upgrade lib60870 to version 2.4.1 (or later) as soon as it is released.
- Verify the patch in a staging environment and capture test logs as audit‑ready evidence.
- Update your software‑bill‑of‑materials (SBOM) and map the remediation to SOC 2 CC6.1/CC7.1 controls.
- Incorporate continuous monitoring of third‑party library versions into your CI/CD pipeline.
Source: CISA Advisory ICS‑A‑26‑211‑11