# CERT-FR flags Moxa protocol gateway flaws

Published: 2026-10-02 · Severity: routine · Sectors: manufacturing, infrastructure, energy
Canonical: https://vorant.io/reports/5728bd41-b21a-5946-8550-c3d97686bc07/cert-fr-flags-moxa-protocol-gateway-flaws

> CERT-FR advises on two vulnerabilities in Moxa MGate protocol gateways enabling data integrity, confidentiality, and security bypass impacts.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Moxa's MGate protocol gateway product line, widely used in industrial environments for protocol conversion between fieldbus and Ethernet networks. The vulnerabilities, tracked as CVE-2026-86325 and CVE-2026-86326, affect a broad range of MGate series devices including the 5101-PBM, 5102-PBM, 5103, 5105-MB-EIP, 5109, 5111, 5114, 5118, 5119, 5216, 5217, EIP3170, EIP3270, MB3170, MB3180, MB3270, MB3280, MB3480, MB3660, W5108 and W5208 series. Most series are affected across all firmware versions, while a few (5217, MB3170, MB3180, MB3270, MB3280, MB3480, MB3660) are only affected in versions prior to specific patched releases.

The flaws can allow an attacker to compromise data confidentiality and integrity and bypass security policy controls on affected devices; the broader risk categories listed by CERT-FR also include remote code execution and remote denial of service, indicating the underlying issues may have significant impact in OT/ICS deployments. Moxa has published advisory MPSA-269540 with patches and a provisional workaround specifically noted for CVE-2026-86326. CERT-FR does not indicate active exploitation in the wild; this is a vendor patch advisory requiring organizations operating Moxa MGate gateways to apply updates or the documented workaround promptly given the industrial control/infrastructure use case of these devices.

## Mentioned in this report

- Vulnerabilities: CVE-2026-86325, CVE-2026-86326

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1250

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5728bd41-b21a-5946-8550-c3d97686bc07/cert-fr-flags-moxa-protocol-gateway-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
