PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9266 Moxa CVE debrief

CVE-2026-9266 is a high-severity vulnerability in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.

Vendor
Moxa
Product
UC-1200A Series
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-12
Advisory published
2026-06-12
Advisory updated
2026-06-12

Who should care

Users of Moxa's industrial computers and controllers should apply the necessary patches to mitigate this vulnerability.

Technical summary

The vulnerability has a CVSS score of 7 and is classified as HIGH severity. It is caused by a missing required cryptographic step in the TPM2 parameter encryption.

Defensive priority

High

Recommended defensive actions

  • Apply patches provided by Moxa to fix the vulnerability.
  • Ensure physical security of devices to prevent invasive access.
  • Monitor for any downstream system impacts, although none are expected.

Evidence notes

The CVE was published on 2026-06-12T11:16:23.297Z and modified on 2026-06-12T16:06:17.027Z. The vendor is likely Moxa, based on the security advisory reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9266 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9266

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9266 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9266

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-266240-cve-2026-9266-missing-required-cryptographic-step-vulnerability-in-industrial-computers

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.