<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MGate 5000 Series - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mgate-5000-series/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 22:52:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mgate-5000-series/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Vulnerabilities in Moxa MGate Protocol Gateways</title><link>https://feed.craftedsignal.io/briefs/2026-10-moxa-advisory/</link><pubDate>Fri, 02 Oct 2026 22:52:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-moxa-advisory/</guid><description>Moxa has disclosed two critical vulnerabilities, CVE-2026-86325 and CVE-2026-86326, affecting MGate 3000 and 5000 series protocol gateways.</description><content:encoded><![CDATA[<p>Moxa has released security advisory AV26-995 regarding two vulnerabilities identified as CVE-2026-86325 and CVE-2026-86326. These vulnerabilities impact the MGate 3000 and MGate 5000 series of protocol gateways, which are commonly utilized in industrial control systems to facilitate communication between different fieldbus and Ethernet protocols. The vulnerabilities originate within the gateway firmware, potentially exposing industrial network infrastructure to exploitation. Because these devices act as critical bridges between IT and OT environments, unpatched vulnerabilities in these gateways represent a significant risk to operational continuity and network integrity. Administrators are advised to monitor the official Moxa security portal for specific firmware update releases and apply them to all affected units within their industrial control system environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in unauthorized access, service disruption, or unauthorized control of traffic passing through the affected MGate gateways. Given the role of these devices in industrial environments, compromise could lead to direct operational impacts, including the interruption of physical processes, loss of visibility into critical assets, or the manipulation of industrial control traffic.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Review the official Moxa security advisory MPSA-269540 for detailed mitigation steps regarding CVE-2026-86325 and CVE-2026-86326.</li>
<li>Prioritize the application of firmware updates on internet-facing or perimeter-integrated MGate gateways.</li>
<li>Implement network segmentation to isolate MGate 3000 and 5000 series devices from unnecessary network traffic until patching is completed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>industrial-control-systems</category><category>vulnerability</category><category>ot-security</category></item></channel></rss>