CVE-2026-66364
Last modified
CVE-2026-66364 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MZ Automation GmbH | libiec61850 | < 1.6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66364?
How severe is CVE-2026-66364?
How do I fix CVE-2026-66364?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66353Improper Neutralization of Input During Web Page Generation …5.3
- CVE-2026-66357httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 72…8.3
- CVE-2026-66358A cross-site scripting vulnerability exists in acmailer, whi…5.1
- CVE-2026-6636A vulnerability was detected in p2r3 convert up to 6998584ac…4.3
- CVE-2026-66360The ISO Presentation layer contains a flaw in the handling o…7.5
- CVE-2026-66362Description: When NGINX Plus is configured as the data plane…8.1
- CVE-2026-66369The GOOSE parser contains an off-by-one boundary-handling fl…6.5
- CVE-2026-6637Stack buffer overflow in PostgreSQL module "refint" allows a…8.8
- CVE-2026-66370URL Redirection to Untrusted Site ('Open Redirect') vulnerab…6.1
- CVE-2026-66372The affected products use insufficiently random values, whic…6.8
- CVE-2026-66373Redis before 8.8.0, in the unusual case where an authenticat…7.5
- CVE-2026-66374Knot Resolver before 6.4.1 allows remote code execution via …8.1
Are you affected by CVE-2026-66364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
