HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Out‑of‑Bounds Read Vulnerabilities (CVE‑2026‑61893, CVE‑2026‑63033) in MZ Automation lib60870 Could Crash Industrial Devices

MZ Automation disclosed two out‑of‑bounds read flaws (CVE‑2026‑61893, CVE‑2026‑63033) in lib60870 2.4.0 that can cause device crashes. For SOC 2‑ready organizations, the issue highlights the need for rigorous third‑party component tracking and audit‑ready remediation evidence.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Out‑of‑Bounds Read Vulnerabilities (CVE‑2026‑61893, CVE‑2026‑63033) in MZ Automation lib60870 Could Crash Industrial Devices

What It Is — Two out‑of‑bounds read bugs were disclosed in MZ Automation’s lib60870 2.4.0. A crafted IEC 60870‑5‑104 I‑frame can cause the library to read past the end of a heap buffer, leading to a crash of any device that uses the library.

Exploitability — No public exploit code has been released, but the CVSS v3 base score is 6.5 (moderate). Successful exploitation is feasible for an attacker who can send malicious IEC 60870‑5‑104 traffic to the target device.

Affected Products — MZ Automation lib60870 version 2.4.0 (open‑source library hosted on GitHub).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The vulnerability maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Demonstrating that you have identified, patched, and documented the fix is essential audit evidence.
  • Continuous Evidence – Maintaining a verifiable record of library version updates and test results satisfies the “monitoring and response” criteria auditors now expect for critical‑infrastructure software.
  • Enterprise Buyer Expectations – Energy and manufacturing customers increasingly require proof that third‑party components are tracked and remediated in real time as part of SOC 2 readiness.

Recommended Actions

  • Upgrade lib60870 to version 2.4.1 (or later) as soon as it is released.
  • Verify the patch in a staging environment and capture test logs as audit‑ready evidence.
  • Update your software‑bill‑of‑materials (SBOM) and map the remediation to SOC 2 CC6.1/CC7.1 controls.
  • Incorporate continuous monitoring of third‑party library versions into your CI/CD pipeline.

Source: CISA Advisory ICS‑A‑26‑211‑11

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →