{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mgate-3000-series/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-86325"},{"id":"CVE-2026-86326"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MGate 3000 Series","MGate 5000 Series"],"_cs_severities":["high"],"_cs_tags":["industrial-control-systems","vulnerability","ot-security"],"_cs_type":"advisory","_cs_vendors":["Moxa"],"content_html":"\u003cp\u003eMoxa has released security advisory AV26-995 regarding two vulnerabilities identified as CVE-2026-86325 and CVE-2026-86326. These vulnerabilities impact the MGate 3000 and MGate 5000 series of protocol gateways, which are commonly utilized in industrial control systems to facilitate communication between different fieldbus and Ethernet protocols. The vulnerabilities originate within the gateway firmware, potentially exposing industrial network infrastructure to exploitation. Because these devices act as critical bridges between IT and OT environments, unpatched vulnerabilities in these gateways represent a significant risk to operational continuity and network integrity. Administrators are advised to monitor the official Moxa security portal for specific firmware update releases and apply them to all affected units within their industrial control system environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in unauthorized access, service disruption, or unauthorized control of traffic passing through the affected MGate gateways. Given the role of these devices in industrial environments, compromise could lead to direct operational impacts, including the interruption of physical processes, loss of visibility into critical assets, or the manipulation of industrial control traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReview the official Moxa security advisory MPSA-269540 for detailed mitigation steps regarding CVE-2026-86325 and CVE-2026-86326.\u003c/li\u003e\n\u003cli\u003ePrioritize the application of firmware updates on internet-facing or perimeter-integrated MGate gateways.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate MGate 3000 and 5000 series devices from unnecessary network traffic until patching is completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T22:52:58Z","date_published":"2026-10-02T22:52:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-moxa-advisory/","summary":"Moxa has disclosed two critical vulnerabilities, CVE-2026-86325 and CVE-2026-86326, affecting MGate 3000 and 5000 series protocol gateways.","title":"Vulnerabilities in Moxa MGate Protocol Gateways","url":"https://feed.craftedsignal.io/briefs/2026-10-moxa-advisory/"}],"language":"en","title":"CraftedSignal Threat Feed - MGate 3000 Series","version":"https://jsonfeed.org/version/1.1"}