CISA published an ICS advisory for the Monta monta.app electric-vehicle charging management platform, used by charging-station operators across the Energy and Transportation Systems sectors and deployed worldwide, listing four vulnerabilities including CVE-2026-95102, scored CVSS v3.1 9.4 CRITICAL: unauthenticated WebSocket endpoints let attackers impersonate charging stations, gaining unauthorised access to sensitive data or performing unauthorised actions with potential privilege escalation. The companion flaws are CVE-2026-97363 (no rate limiting on authentication attempts, enabling brute-force or denial-of-service), CVE-2026-97212 (predictable session identifiers allowing users to authenticate as others) and CVE-2026-93474 (charging-station authentication identifiers publicly accessible via web mapping platforms). Successful exploitation could enable attackers to gain administrative control over vulnerable charging stations or disrupt charging services through denial-of-service. The advisory — reported by an anonymous researcher — covers all versions (vers:all/*), states no known public exploitation has been reported to CISA at this time, and provides mitigation guidance: keep charging systems off the internet, behind firewalls and isolated from business networks. This is a patched-vulnerability disclosure, not a reported attack.
| Attribute | Detail |
|---|---|
| Sector | Energy & Utilities |
| Date | 2026-10-02 |
| Source | CISA ICS Advisory ICSA-26-274-02 |
| Reliability | Tier 1 |
| CVEs | CVE-2026-93474, CVE-2026-95102, CVE-2026-97212, CVE-2026-97363 |