Security Advisory
CVE-2026-85434
9.1
CRITICAL
Vulnerability Description
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
Published Date
September 3, 2026
Official Source
NIST NVD Advisory