VORANT. Threat Intelligence Research Sign in Create a free account

CERT-FR flags Moxa protocol gateway flaws

routine vulnerability manufacturinginfrastructureenergy

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advises on two vulnerabilities in Moxa MGate protocol gateways enabling data integrity, confidentiality, and security bypass impacts.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Moxa's MGate protocol gateway product line, widely used in industrial environments for protocol conversion between fieldbus and Ethernet networks. The vulnerabilities, tracked as CVE-2026-86325 and CVE-2026-86326, affect a broad range of MGate series devices including the 5101-PBM, 5102-PBM, 5103, 5105-MB-EIP, 5109, 5111, 5114, 5118, 5119, 5216, 5217, EIP3170, EIP3270, MB3170, MB3180, MB3270, MB3280, MB3480, MB3660, W5108 and W5208 series. Most series are affected across all firmware versions, while a few (5217, MB3170, MB3180, MB3270, MB3280, MB3480, MB3660) are only affected in versions prior to specific patched releases.

The flaws can allow an attacker to compromise data confidentiality and integrity and bypass security policy controls on affected devices; the broader risk categories listed by CERT-FR also include remote code execution and remote denial of service, indicating the underlying issues may have significant impact in OT/ICS deployments. Moxa has published advisory MPSA-269540 with patches and a provisional workaround specifically noted for CVE-2026-86326. CERT-FR does not indicate active exploitation in the wild; this is a vendor patch advisory requiring organizations operating Moxa MGate gateways to apply updates or the documented workaround promptly given the industrial control/infrastructure use case of these devices.

Mentioned in this report

Vulnerabilities CVE-2026-86325CVE-2026-86326

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1250

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,646 reports from 152 sources, 506 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs