SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85435

CRITICAL · CVSS 9.1 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

MOOS-IvP uFldNodeBroker versions up to 24.8.1 are vulnerable due to inadequate validation of TRY_SHORE_HOST messages, enabling attackers to inject malicious shore route messages. This flaw allows unauthorized access to bridged vehicle traffic, including sensitive sensor data and control information, posing a significant risk to operational security. Organizations utilizing this software should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85435
Severity
CRITICAL
CVSS
9.1
EPSS
0.17%

Original NVD Description

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.