PatchSiren cyber security CVE debrief
CVE-2026-9266 Moxa CVE debrief
CVE-2026-9266 is a high-severity vulnerability in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.
- Vendor
- Moxa
- Product
- UC-1200A Series
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-12
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-12
- Advisory updated
- 2026-06-12
Who should care
Users of Moxa's industrial computers and controllers should apply the necessary patches to mitigate this vulnerability.
Technical summary
The vulnerability has a CVSS score of 7 and is classified as HIGH severity. It is caused by a missing required cryptographic step in the TPM2 parameter encryption.
Defensive priority
High
Recommended defensive actions
- Apply patches provided by Moxa to fix the vulnerability.
- Ensure physical security of devices to prevent invasive access.
- Monitor for any downstream system impacts, although none are expected.
Evidence notes
The CVE was published on 2026-06-12T11:16:23.297Z and modified on 2026-06-12T16:06:17.027Z. The vendor is likely Moxa, based on the security advisory reference.
Official resources
-
CVE-2026-9266 CVE record
CVE.org
-
CVE-2026-9266 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
CVE-2026-9266 was published on 2026-06-12T11:16:23.297Z.