CVE-2026-85433: Themoos Essential-Moos
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
Affected products
- Themoos Essential-Moos: up to and including 10.0.1
Published 2026-09-03. Last modified 2026-09-14.