CVE-2026-85455: Themoos Core-Moos

High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.

Affected products

  • Themoos Core-Moos: up to and including 10.4.0

Published 2026-09-03. Last modified 2026-09-08.