High‑Severity DoS Vulnerability (CVE‑2026‑16002) in MZ Automation lib60870 Threatens Critical Infrastructure
What It Is – An out‑of‑bounds read flaw (CVE‑2026‑16002) in MZ Automation’s lib60870 library (versions ≤ 2.4.0) can cause the parsing process to crash, resulting in a denial‑of‑service condition.
Exploitability – CVSS v3.1 8.2 (High) and CVSS v4.0 8.8 (High); the vulnerability is exploitable remotely with no authentication or user interaction required. No public exploit code has been released, but the severity and network‑vector rating indicate a realistic threat.
Affected Products – MZ Automation lib60870 ≤ 2.4.0 (open‑source library used in IEC 60870‑5‑101/104 implementations for SCADA/ICS).
Why It Matters for Compliance & Audit Readiness
- Availability controls (SOC 2 CC6.1): A DoS in a protocol library directly impacts system uptime, a key audit criterion for service‑operation reliability.
- Continuous control monitoring: Demonstrating that you have an automated patch‑management pipeline that captures remediation evidence satisfies auditors looking for “real‑time” evidence of control effectiveness.
- Supply‑chain diligence: The library is often bundled by third‑party vendors; tracking its version across all downstream assets is essential for vendor‑risk evidence in a SOC 2 audit.
Recommended Actions
- Upgrade lib60870 to version 2.4.1 or later on all affected systems.
- Verify the patch deployment with an automated inventory scan and map the change to SOC 2 CC6.1 (System Operations – Availability).
- Record the remediation in your change‑management system and retain the vendor advisory as audit evidence.
Source: CISA Advisory ICSA‑26‑204‑07