Moxa issued security advisories for multiple industrial and embedded product families, including the UC Series, V Series, VM-1220 Series, ioThinx 4530 Series, AIG Series, BXP Series, DRP-A100/DRP-C100 Series, and RKP Series. A Canadian Centre for Cyber Security notice highlighted the disclosures and directed operators to review Moxa’s published advisories and apply vendor-provided updates.
The advisories include CVE-2026-46333, identified as the "ssh-keysign-pwn" vulnerability in the Linux kernel. The issue affects control-system environments using impacted Moxa platforms, raising patching and asset-review priorities for organizations that rely on these devices in operational technology and embedded deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Canadian Centre for Cyber Security notice summarized Moxa security advisories published on July 24, 2026, highlighting affected product families including the UC, V, VM-1220, ioThinx 4530, AIG, BXP, DRP-A100/DRP-C100, and RKP series. The notice specifically referenced CVE-2026-46333, described as the "ssh-keysign-pwn" vulnerability, and advised administrators to review the advisories and apply updates.
Moxa published security advisory AV26-742 covering vulnerabilities affecting multiple industrial and embedded product lines. The advisory is the primary vendor disclosure referenced by later reporting.
Moxa published security advisory MPSA-267410 for CVE-2026-46333, describing the 'ssh-keysign-pwn' local privilege escalation issue affecting multiple Moxa product series running Moxa Industrial Linux or Debian-based builds. The advisory provided interim mitigations, noted MIL1 firmware updates were not yet available, and directed some customers to update instructions in MPSA-263140.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcemoxa.com
Open sourcemoxa.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.