MZ Automation lib60870

Summary

CISA has alerted that successful exploitation of vulnerabilities in MZ Automation lib60870 could crash the device being accessed. Specifically, CVE-2026-61893 and CVE-2026-63033 affect lib60870 version 2.4.0, allowing an out-of-bounds read that leads to a crash.

IFF Assessment

FOE

These vulnerabilities enable attackers to crash critical infrastructure devices, posing a significant risk to operational stability.

Severity

6.5 Medium

Defender Context

Defenders in critical infrastructure sectors such as Energy, Water and Wastewater, and Critical Manufacturing should be aware of these vulnerabilities. The affected lib60870 library is widely deployed globally. Prompt patching or mitigation is crucial to prevent denial-of-service attacks.

Read Full Story →