Which monta.app versions are affected by the October 01, 2026 CISA advisory?

If you use Monta monta.app with charging-station infrastructure, the key question is whether your deployed version appears in CISA’s October 01, 2026 advisory.
The direct answer
CISA says every listed monta.app version in the advisory is affected.
The advisory ties those listed versions to four CVEs:
- CVE-2026-95102
- CVE-2026-97363
- CVE-2026-97212
- CVE-2026-93474
The context provided here does not include the advisory’s full version table, so this post cannot safely name version numbers beyond what CISA listed in the official notice. The practical answer is: if your monta.app version appears in CISA’s advisory, treat it as affected.
Who should check
The affected product is associated with the Energy and Transportation Systems critical infrastructure sectors. CISA also describes worldwide deployment, with the company headquartered in the Netherlands.
That means the version check is not limited to one country or one kind of local operator. Any organization running monta.app in a charging-station environment should compare its deployed version against CISA’s listed versions.
Why the version match matters
CISA describes the possible impact as unauthorized administrator-level control of vulnerable charging stations or denial-of-service disruption of charging services.
One weakness described in the advisory involves WebSocket endpoints without adequate authentication. CISA says that could let attackers pose as charging stations and take unauthorized actions.
Because advisory details can change, use the official CISA page as the current source when confirming the affected version list.
What should operators of vulnerable Monta charging stations do after the CISA advisory?
Operators should start by treating the CISA advisory as an asset-check and exposure-review item, not as a general news item.
What to do first
Check whether your deployed monta.app version is one of the versions listed in CISA’s October 01, 2026 advisory.
CISA says every listed monta.app version is affected by:
- CVE-2026-95102
- CVE-2026-97363
- CVE-2026-97212
- CVE-2026-93474
The provided context does not include a patch version, workaround, vendor instruction, or deadline. So the confirmed action is to verify whether your environment is in scope by comparing your deployed version against the official CISA advisory.
What risk to plan around
CISA describes two main kinds of potential impact:
- Unauthorized administrator-level control of vulnerable charging stations
- Denial-of-service disruption of charging services
For operators, that points to two practical areas to review: who can control charging-station functions, and whether charging services could be disrupted if vulnerable systems are exposed.
What to verify in your environment
The advisory context specifically mentions WebSocket endpoints without adequate authentication. CISA says this could allow attackers to impersonate charging stations and perform unauthorized actions.
If your environment uses the affected monta.app versions, check the official advisory for the latest vendor and CISA guidance before making operational changes. The source page is the safest place to confirm whether CISA has added or revised instructions.
How could unauthenticated WebSocket endpoints affect Monta charging stations?

The WebSocket issue matters because CISA says it could let an attacker act like a charging station when proper authentication is missing.
How the weakness works in plain terms
CISA describes WebSocket endpoints without adequate authentication as one weakness in the affected monta.app issue.
A WebSocket endpoint is a communication path used by software systems. If that path does not adequately confirm who is connecting, CISA says attackers could pose as charging stations.
What that could allow
According to the advisory context, posing as a charging station could let attackers perform unauthorized actions.
CISA also describes the wider potential impact of the affected monta.app versions as:
- Unauthorized administrator-level control of vulnerable charging stations
- Denial-of-service disruption of charging services
The context does not identify which CVE maps to every specific technical behavior, so it would be inaccurate to assign details beyond what CISA confirmed in the advisory summary.
What to watch next
This is a technical advisory, and details may be updated. If you manage Monta-connected charging infrastructure, compare your installed version with CISA’s listed affected versions and review the official page for current guidance.
What is the potential impact of CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474 on Monta deployments?

CISA’s October 01, 2026 advisory groups four CVEs under the affected monta.app versions. The practical impact is about control and service availability.
Confirmed potential impact
CISA describes the possible effect of CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474 as:
- Unauthorized administrator-level control of vulnerable charging stations
- Denial-of-service disruption of charging services
That means the advisory is relevant both to security control of charging equipment and to the continuity of charging services.
Affected deployment context
The affected product is tied to the Energy and Transportation Systems critical infrastructure sectors. CISA also identifies deployment as worldwide and lists the company headquarters as the Netherlands.
One described weakness involves WebSocket endpoints that do not have adequate authentication. CISA says that weakness could allow attackers to impersonate charging stations and take unauthorized actions.
What the advisory does not confirm here
The provided context does not include individual technical breakdowns for each CVE, exploit details, patch instructions, or a full affected-version table. For those specifics, check the CISA advisory directly and use the latest official version of the notice.
Sources / Learn more
Related reading
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- How should organizations mitigate CVE-2026-34223 in Siemens Desigo CC family V6 and V7?; Which Siemens Desigo CC versions are affected by the client code execution vulnerability?; How can specially crafted graphics documents lead to client code execution in Desigo CC?; What changed after CISA’s September 22, 2026 advisory for Siemens Desigo CC family?
- How do Siemens WTV676 and WTV776 operators check whether their Web Interface version is affected?; What should operators do if a Siemens WTV676 or WTV776 device enters protection mode and Web Access stops working?; Which Siemens WTV676 and WTV776 updates address the CISA denial of service advisory?
- How should Siemens Siveillance Control and Siveillance Control Pro users address CVE-2026-50093?; Which Siveillance Control and Siveillance Control Pro versions are affected by CVE-2026-50093?; How could the Open Interface Services web module vulnerability lead to root-level access?; What changed in the September 22, 2026 CISA advisory for Siemens Siveillance Control?

Leave a Reply