SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85446

HIGH · CVSS 7.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MOOS-IvP versions up to 24.8.1 are vulnerable to a quadratic processing flaw in uFldNodeComms, allowing attackers to exploit unbounded distinct node names in reports. This can lead to significant delays or complete disruption of legitimate node report distributions, impacting system performance and reliability. Organizations using affected versions should prioritize remediation to mitigate potential service disruptions and maintain operational integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85446
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.