[Control Systems] Moxa security advisory (AV26-742)
Serial number: AV26-742 Date: July 24, 2026 On July 24, 2026, Moxa published security advisories to address vulnerabilities in the following products: Moxa UC Series – multiple versions and models Moxa V Series – multiple versions and models Moxa VM-1220 Series – version MIL3 v1.1.0 and prior Moxa ioThinx 4530 Series – version MIL3 v2.1 and prior Moxa AIG Series – multiple versions and models Moxa BXP Series – multiple versions and models Moxa DRP-A100 Series / DRP-C100 Series – version Debian 11 V1.0 Moxa RKP Series – multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. CVE-2026-46333: ssh-keysign-pwn Vulnerability in Linux Kernel Moxa Security Advisories
CSIRTS triage
- What
- There are vulnerabilities in multiple Moxa products.
- Who is affected
- Users and administrators of Moxa UC Series and other affected models.
- Urgency
- Remediation is encouraged as vulnerabilities may pose risks, although exploitation status is currently unknown.
- Action
- Users should review the provided web links and apply necessary updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Moxa UC Series
Get an email when a new Moxa UC Series advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-moxa-security-advisory-av26-742
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-463331.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-46333 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedSiemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa
- medium[UPDATE] [medium] Linux Kernel: Vulnerability Allows Bypassing Security Measurescert-bund
- unknownVulnerability in Moxa products (July 24, 2026)cert-fr-avis
- highUSN-8569-1: Linux kernel (HWE) vulnerabilitiesubuntu
- unknownMultiple vulnerabilities in F5 products (July 16, 2026)cert-fr-avis
- unknownexploitedUSN-8528-1: Linux kernel (Xilinx ZynqMP) vulnerabilitiesubuntu
- unknownMultiple vulnerabilities in Red Hat Linux kernel (July 3, 2026)cert-fr-avis
- unknownRedHat Linux Kernel Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in the Ubuntu Linux kernel (June 26, 2026)cert-fr-avis
- criticalexploitedImpact of Linux Kernel vulnerabilities on B&R productscisa
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30