CVE-2026-86326: Moxa MGate gateways accept unsigned firmware
Moxa disclosed CVE-2026-86326 (CVSSv4 8.6) on October 2, 2026: its MGate industrial protocol gateways do not verify the cryptographic authenticity of firmware images, so a modified image installs and persists across later updates. No firmware fix existed at disclosure; all versions of the MB3000, EIP3000, 5000 and retired W5108/W5208 lines are affected.
- CVSSv4 score 8.6, advisory MPSA-269540, disclosed October 2, 2026
- Exploitation requires high privileges, so it works after authentication
- Malicious code persists across subsequent firmware updates
- No patch; Moxa urges restricting management interface access
Read next
Security