


Perceptive Security
SOC/SIEM Consultancy

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. Thi…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 15:06:28
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure, Mobile & IoT
CVE-2026-44092 describes an unauthenticated remote code injection vulnerability in the ModbusServer application. The flaw exists because the application fails to validate input fetched from MQTT messages. An unauthenticated remote attacker can exploit this to inject malicious input into the system. Successful exploitation may result in integrity and availability loss. The vulnerability is documented by both NVD/NIST and CERT VDE. No authentication is required to exploit this vulnerability, making it particularly dangerous in exposed environments. The issue highlights risks in ICS/SCADA environments where Modbus and MQTT protocols are commonly used together. The advisory VDE-2026-008 provides additional context from CERT VDE.
Technical details
Mitigation steps:
Affected products:
ModbusServer
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
