PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9266 Moxa CVE debrief

CVE-2026-9266 is a high-severity vulnerability in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.

Vendor
Moxa
Product
UC-1200A Series
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-12
Advisory published
2026-06-12
Advisory updated
2026-06-12

Who should care

Users of Moxa's industrial computers and controllers should apply the necessary patches to mitigate this vulnerability.

Technical summary

The vulnerability has a CVSS score of 7 and is classified as HIGH severity. It is caused by a missing required cryptographic step in the TPM2 parameter encryption.

Defensive priority

High

Recommended defensive actions

  • Apply patches provided by Moxa to fix the vulnerability.
  • Ensure physical security of devices to prevent invasive access.
  • Monitor for any downstream system impacts, although none are expected.

Evidence notes

The CVE was published on 2026-06-12T11:16:23.297Z and modified on 2026-06-12T16:06:17.027Z. The vendor is likely Moxa, based on the security advisory reference.

Official resources

CVE-2026-9266 was published on 2026-06-12T11:16:23.297Z.