CVE-2026-85444: Moos-Ivp
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffer bounds and access adjacent memory.
Affected products
- Moos-Ivp Moos-Ivp: up to and including 24.8.1
Published 2026-09-03. Last modified 2026-09-08.