PatchSiren cyber security CVE debrief
CVE-2026-9266 Moxa CVE debrief
CVE-2026-9266 is a high-severity vulnerability in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.
- Vendor
- Moxa
- Product
- UC-1200A Series
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-12
- Original CVE updated
- 2026-06-12
- Advisory published
- 2026-06-12
- Advisory updated
- 2026-06-12
Who should care
Users of Moxa's industrial computers and controllers should apply the necessary patches to mitigate this vulnerability.
Technical summary
The vulnerability has a CVSS score of 7 and is classified as HIGH severity. It is caused by a missing required cryptographic step in the TPM2 parameter encryption.
Defensive priority
High
Recommended defensive actions
- Apply patches provided by Moxa to fix the vulnerability.
- Ensure physical security of devices to prevent invasive access.
- Monitor for any downstream system impacts, although none are expected.
Evidence notes
The CVE was published on 2026-06-12T11:16:23.297Z and modified on 2026-06-12T16:06:17.027Z. The vendor is likely Moxa, based on the security advisory reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9266 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9266
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9266 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9266
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-266240-cve-2026-9266-missing-required-cryptographic-step-vulnerability-in-industrial-computers
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.