# Moxa Linux devices hit by SSH keysign flaw

Published: 2026-07-24 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/fe8a507c-3aed-5a4c-a221-731e477c900c/moxa-linux-devices-hit-by-ssh-keysign-flaw

> A privilege escalation vulnerability in the Linux kernel's SSH keysign component affects Moxa products, per a CERT-FR advisory.

CERT-FR issued an advisory relaying a Moxa security bulletin (MPSA-267410) concerning CVE-2026-46333, a vulnerability affecting the ssh-keysign component in the Linux kernel as implemented in certain Moxa products. The flaw allows an attacker to achieve privilege escalation on affected systems.

No technical exploitation details, proof-of-concept, or evidence of in-the-wild attacks are included in the advisory. Affected organizations should consult Moxa's security bulletin for the specific list of impacted products and apply vendor-supplied patches once available.

## Mentioned in this report

- Vulnerabilities: CVE-2026-46333 (weaponized)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0931

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fe8a507c-3aed-5a4c-a221-731e477c900c/moxa-linux-devices-hit-by-ssh-keysign-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
