CVE-2026-86326: Moxa MGate Flaw Has No Firmware Fix
On 2 October 2026 Moxa disclosed CVE-2026-86326 (CVSSv4 8.6) in MGate MB3000, EIP3000 and 5000 gateways: the device does not verify the cryptographic authenticity of firmware images. With no patch available, mitigation relies on restricting management access and controlling firmware provenance.
- CVE-2026-86326 carries a CVSSv4 score of 8.6
- All firmware versions of MGate MB3000, EIP3000 and 5000 are affected
- Only the sibling CVE-2026-86325 has fixes available
- ZoomEye shows 18 results for app="Moxa MGate"
Read next
Security