VORANT. Threat Intelligence Sign in Get the full feed

Moxa serial device servers auth bypass flaw

medium vulnerability infrastructuremanufacturingenergy

CVE-2026-10831 affects Moxa CN2600 and NPort 6000 serial device servers, enabling remote denial of service and security policy bypass.

A vulnerability has been identified in Moxa serial device server products that allows attackers to bypass security policies and trigger remote denial of service conditions. The flaw, tracked as CVE-2026-10831, is described as an improper authorization vulnerability affecting the CN2600 Series running versions prior to 4.6.11 and NPort 6000 Series running versions prior to 2.3.9.

Moxa has released patches addressing this vulnerability in the affected product lines. Organizations running vulnerable versions of these serial device servers should apply the vendor-supplied updates to mitigate the risk of unauthorized access and service disruption.

Serial device servers are commonly deployed in industrial and critical infrastructure environments to enable network connectivity for serial devices, making this vulnerability relevant to operational technology networks where availability and access control are critical security requirements.

Mentioned in this report

Vulnerabilities CVE-2026-10831

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0763

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free