chiprook
← Security
SecurityOctober 5, 2026, 21:40

CVE-2026-86326: Moxa MGate gateways accept unsigned firmware

Moxa disclosed CVE-2026-86326 (CVSSv4 8.6) on October 2, 2026: its MGate industrial protocol gateways do not verify the cryptographic authenticity of firmware images, so a modified image installs and persists across later updates. No firmware fix existed at disclosure; all versions of the MB3000, EIP3000, 5000 and retired W5108/W5208 lines are affected.

CVE-2026-86326: Moxa MGate gateways accept unsigned firmware
#Moxa#MGate
Read next
Security

CVE-2026-76442: Unbounded Input in Cisco Secure Email Gateway Causes DoS

Security

CVE-2026-76461: SQL injection in Cisco email gateway grants root

Security

Darktrace: AI agent history is unsigned and writable by anyone

Software

Mass segfaults on a ZFS host: not bad RAM, an unsigned underflow in zfs_fillpage()