On July 30, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published ICS Advisory ICSA-26-211-10 regarding vulnerabilities in MZ Automation GmbH's libiec61850 library. According to CISA's official notice, successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on affected devices.
Libiec61850 is a library used to implement IEC 61850 communication protocols, a standard widely deployed in electrical substations, power distribution systems, and other critical infrastructure. DoS attacks against OT devices in these environments can disrupt monitoring, control, and automation functions—potentially affecting power grid visibility and operational response times.
The advisory is marked as emerging status with a single official source (CISA). The full technical details, affected version numbers, and mitigation guidance are available through CISA's official advisory page and the CSAF document hosted on GitHub.
What matters here: This is not a widespread active exploit report—yet. This is notification that the vulnerability exists and that patches or mitigations need to be applied in OT environments that depend on libiec61850. Infrastructure operators managing IEC 61850 deployments should treat this as a priority review item, particularly if the affected library is in use in their systems.
The criticality hinges on whether this library is in active use in your environment. If your organization runs power distribution, substation automation, or related OT systems, cross-reference your software bill of materials (SBOM) against the affected versions listed in the CISA advisory. The window to patch or isolate vulnerable instances before broader threat actor interest is typically narrow.

