CVE-2026-15579
An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly long input, triggering a buffer overflow that can cause the authentication process to crash and result in a Denial of Service (DoS) attack.
- Published Sep 18, 2026
- CVSS 8.8 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- [Control Systems] Moxa security advisory (AV26-938) Canadian Centre for Cyber Security ·
- Vulnerability in Moxa products CERT-FR ·