SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85455

HIGH · CVSS 8.2 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A buffer over-read vulnerability in the CMOOSCommPkt component of MOOS core-moos versions up to 10.4.0 allows attackers to exploit out-of-bounds memory access during packet deserialization. By establishing a TCP connection to the MOOSDB port and sending a specially crafted short packet, an attacker can read sensitive memory contents prior to authentication. Organizations using affected versions should prioritize patching this vulnerability to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85455
Severity
HIGH
CVSS
8.2
EPSS
0.36%

Original NVD Description

MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.