SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85433

CRITICAL · CVSS 9.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability allows unauthorized reconfiguration of network routes and listeners in the MOOS essential-moos pShare component, enabling attackers to send specially crafted PSHARE_CMD messages. This can lead to the opening of new listeners on arbitrary addresses and the redirection of bus traffic to malicious destinations, posing a critical risk to network integrity. Organizations using affected versions should prioritize immediate remediation to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85433
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%

Original NVD Description

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.