Moxa industrial computers expose data via cryptographic flaw
A cryptographic vulnerability in Moxa industrial computers allows attackers to compromise data confidentiality across multiple UC and V-series models.
CERT-FR has published an advisory regarding CVE-2026-9266, a missing cryptographic step vulnerability affecting multiple Moxa industrial computer product lines. The flaw impacts V2406C WL models, UC-1200A, UC-2200A, UC-3400A, UC-4400A, UC-8200 series, and V1200, V3200, and V3400 series running various versions prior to MIL3.4.1, MIL4.0.0, or MIL3 depending on the product line.
The vulnerability enables attackers to compromise the confidentiality of data on affected systems. Moxa has released security patches addressing the issue, detailed in security advisory MPSA-266240 published on June 12, 2026. Organizations operating affected industrial computing equipment should consult the vendor bulletin and apply the latest security updates to mitigate the risk.
Given the industrial nature of these systems and their potential deployment in critical infrastructure environments, organizations should prioritize patching efforts while following appropriate change management procedures for operational technology environments.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0743
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free