CVE-2026-86325

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface could supply a specially crafted account name that exceeds the size of the internal stack buffer, resulting in corruption of program execution flow. Successful exploitation could allow an attacker to read sensitive information from device memory, including credentials, modify arbitrary memory contents, and disrupt device availability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-10-02); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-10-02: 2Mentions · 2026-10-03: 210-0210-03
Referenced assets3 URLs
Full discourse4 posts
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Kritische Schwachstellen in Protokoll-Gateways und Apache Thrift: CVE-2026-86325 und CVE-2026-91135 #apachethrift #cve202686325 #cve202691135 #protokollgateways #theadertransport https://cybersecurity-news.de/kritische-schwachstellen-protokoll-gateways-apache-thrift-cve-2026-86325-cve-2026-91135

    0000011
    15 followersView on X
  • Sami Laiho@samilaiho

    CVE-2026-86325, CVE-2026-86326: Two Vulnerabilities in Moxa Protocol Gateways URL: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-269540-cve-2026-86325,-cve-2026-86326-two-vulnerabilities-in-protocol-gateways Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.4

    00000407
    30.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Moxa MGate vulnerabilities CVE-2026-86325 (CVSS 9.4) and CVE-2026-86326 hit MGate protocol gateway firmware. See affected versions and fixes. #Moxa #MGate #CVE202686325 #CVE202686326 #ICSSecurity #OTSecurity #Vulnerability https://securityonline.info/moxa-mgate-vulnerabilities/

    00000403
    13.0K followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-86325 Vendor → Unknown Severity → Critical — CVSS 9.4 Product → Unknown Date → 2026-10-02 A critical vulnerability (Stack-based Buffer Overflow) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000072
    437 followersView on X

Explore more