CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[Control Systems] Moxa security advisory (AV26-742)

unknownCVE-2026-46333
Serial number: AV26-742 Date: July 24, 2026 On July 24, 2026, Moxa published security advisories to address vulnerabilities in the following products: Moxa UC Series – multiple versions and models Moxa V Series – multiple versions and models Moxa VM-1220 Series – version MIL3 v1.1.0 and prior Moxa ioThinx 4530 Series – version MIL3 v2.1 and prior Moxa AIG Series – multiple versions and models Moxa BXP Series – multiple versions and models Moxa DRP-A100 Series / DRP-C100 Series – version Debian 11 V1.0 Moxa RKP Series – multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. CVE-2026-46333: ssh-keysign-pwn Vulnerability in Linux Kernel Moxa Security Advisories

CSIRTS triage

What
There are vulnerabilities in multiple Moxa products.
Who is affected
Users and administrators of Moxa UC Series and other affected models.
Urgency
Remediation is encouraged as vulnerabilities may pose risks, although exploitation status is currently unknown.
Action
Users should review the provided web links and apply necessary updates.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Moxa UC Series

Get an email when a new Moxa UC Series advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-moxa-security-advisory-av26-742

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-46333coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security