CVE-2026-85424: Schwachstellen-Eintrag (NVD)
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 222 |
CVE-2026-85424 | themoos core-moos up to 10.4.0 improper authentication (EUVD-2026-70816)
A vulnerability classified as critical has been found in themoos core-moos up to 10.4.0. This vulnerability affects unknown code. The manipulation leads to improper authentication. This vulnerability is documented as CVE-2026-85424. The att