CVE-2026-85454: Themoos Core-Moos
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution.
Affected products
- Themoos Core-Moos: up to and including 10.4.0
Published 2026-09-03. Last modified 2026-09-08.