MOXA has disclosed two vulnerabilities affecting its MGate protocol gateways, with the company issuing advisories on 2 October 2026. The more severe flaw, CVE-2026-86325, is a stack-based buffer overflow in the account management interface caused by insufficient length validation of the account_name parameter. An overlong account name could overflow a stack buffer, potentially allowing a read of credentials from memory, memory alteration, or a device crash.
The second flaw, CVE-2026-86326, relates to missing firmware signature verification, enabling a privileged attacker to install tampered firmware images that could execute unauthorized code and persist across updates. At present, there is no public proof of concept or in-the-wild exploitation, and neither CVE is listed in the CISA KEV catalog as exploited.
Affected products and fixes are detailed in Moxa’s advisories. CVE-2026-86325 impacts multiple MGate MB3170/MB3270 firmware releases (v4.7 and earlier), MB3180 (v2.7 and earlier), MB3280 (v4.6 and earlier), MB3480 (v4.5 and earlier), MB3660 (v3.4 and earlier), and MB5217 (v1.5 and earlier). CVE-2026-86326 affects all firmware versions across the MGate MB3000, EIP3000 and 5000 lines, with the W5108/W5208 Series also implicated.
Patches are available for CVE-2026-86325, requiring upgrades to specific sub-versions (for example, MB3170/MB3270 v4.7.1, MB3180 v2.7.1, MB3280 v4.6.3, MB3480 v4.5.1, MB3660 v3.4.5, or MB5217 v1.5.5). There is no firmware fix yet for CVE-2026-86326; organisations are advised to obtain firmware only from official Moxa sources and to tighten access to management interfaces to reduce exposure.