Cyber warning issued for MZ Automation’s lib60870 library
A critical out-of-bounds read flaw in MZ Automation’s lib60870 library can crash parsing processes and trigger denial-of-service attacks, according to a joint advisory by CISA and the vendor.
Source: CISA · July 24, 2026 at 11:01 PM · AI-assisted report
KUALA LUMPUR, 25 JULY 2026 —
Listen to this article
DomainFork Audio · read aloud
A critical out-of-bounds read flaw in MZ Automation’s lib60870 library can crash parsing processes and trigger denial-of-service attacks, according to a joint advisory by CISA and the vendor.
Market Impact
Malaysian operators using lib60870 in critical-infrastructure sectors such as energy and water need to check exposure immediately, since many downstream control systems rely on IEC 60870-5-104 stacks for telemetry and command-and-control.
The flaw, tracked as CVE-2026-16002, carries a CVSS v3.1 score of 8.2 and affects all versions of lib60870 prior to 2.4.1. Successful exploitation would let an unauthenticated attacker on the network force a crash by sending malformed frames, disrupting grid or pipeline monitoring.
MZ Automation said users should update to version 2.4.1 or later and isolate affected devices behind firewalls. CISA recommends segmenting operational networks, using VPNs for remote access, and reviewing incident-detection signatures in ICS-TIP-12-146-01B.
No known in-the-wild attacks have been reported, but the high base score and ease of exploitation make patching urgent for regional utilities and Malaysian industrial firms that integrate the library into supervisory-control software.