Daily OT Security News: August 01, 2026

Five concise OT/ICS advisories from the latest official CISA ICS advisory batch (dated July 30, 2026) for OT and cyber-physical defenders, covering vendor updates, protocol flaws, and recommended mitigations.

MZ Automation lib60870 vulnerabilities could crash affected devices

CISA reports that lib60870 version 2.4.0 is affected by CVE-2026-61893 and CVE-2026-63033, where crafted IEC 60870-5-104 I-frames can trigger out-of-bounds reads and crash targeted devices. Affected sectors include energy, water and wastewater, critical manufacturing, and chemical; MZ Automation recommends updating to version 2.4.1 when it is available. No known public exploitation was reported in the advisory.

Source: CISA ICS Advisory

MZ Automation libiec61850 flaws expose energy-sector deployments to denial of service

CISA states that libiec61850 versions earlier than 1.6.2 are affected by eight vulnerabilities, including issues where malformed GOOSE multicast frames and MMS/TCP port 102 inputs can cause out-of-bounds reads and terminate service processes. CISA identifies the energy sector as impacted and advises updating to libiec61850 version 1.6.2. No known public exploitation was reported in the advisory.

Source: CISA ICS Advisory

Hard-coded TLS keys in Watchfire controller software could enable controller compromise

CISA describes CVE-2026-5846 affecting specified Watchfire BC550, BC750, BC760, and BC760DC controller software versions where self-signed, hard-coded RSA private keys and certificates are embedded in plaintext in firmware patch binaries and used by the web-management interface. The advisory warns that malicious firmware could be delivered via updates to gain full control of a controller and notes Watchfire issued version-specific patches. No known public exploitation was reported in the advisory.

Source: CISA ICS Advisory

o6 Automation open62541 vulnerabilities could enable denial of service, information disclosure, or potential code execution

CISA lists affected open62541 Windows/Linux releases spanning 1.3.0–1.3.17, 1.4.0–1.4.16, 1.5.0–1.5.4, and master, and describes four CVEs including an integer underflow in PubSub signature verification, an integer-overflow out-of-bounds write, a TransferSubscriptions use-after-free, and an out-of-bounds memory read. CISA identifies critical manufacturing, energy, and transportation sectors and the vendor recommends updating to the newest version. No known public exploitation was reported in the advisory.

Source: CISA ICS Advisory

Mitsubishi Electric CC-Link IE TSN integrity flaw affects a broad industrial-product set

CISA reports CVE-2026-13584 affects a wide range of Mitsubishi Electric products implementing CC-Link IE TSN, including MELSEC controllers, modules, servo systems, inverters, industrial computers, and HMIs. The advisory states an attacker on the same network segment may tamper with communication data by sending specially crafted packets under specific timing conditions, potentially causing denial of service or incorrect control operation, and advises evaluating vendor mitigations and network segmentation. No known public exploitation was reported in the advisory.

Source: CISA ICS Advisory

Prioritize identifying exposed OT assets, applying vendor mitigations or updates, and conducting safe, tested OT change management before deploying fixes in production environments.

Share this