Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
L L N L N L L L 1.9 .0012 2.2 —
AFFECTED
Product Versions Fixed
libiec61850 1.6.0 – 1.6.2
TIMELINE
Aug 6 Reserved by VulDB
Aug 6 Published (CNA: VulDB)
Aug 7 EXPLOIT PUBLISHED — CVE-2026-19108 (MZ Automation libiec61850). Public exploit reference added.
Description
A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 6, 2026 | Reserved | Reserved by VulDB |
| August 6, 2026 | Published | Published (CNA: VulDB) |
| August 7, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-19108 (MZ Automation libiec61850). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| MZ Automation | libiec61850 | — | 1.6.0 | 1.6.2 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19108 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.