CISA Issues Advisory for Four Critical Vulnerabilities in Monta monta.app Charging Station Software
Multiple security flaws could allow unauthorized administrative control and service disruption of electric vehicle charging infrastructure worldwide.
Key Takeaways
- CISA advisory ICSA-26-274-02 discloses four vulnerabilities in Monta monta.app affecting all versions.
- CVSS scores range from 7.5 (High) to 9.4 (Critical), with three Critical and one High severity rating.
- No confirmed active exploitation in the wild as of publication, but design flaws pose significant risk.
- Affected sectors include Energy and Transportation Systems; deployment is worldwide.
- Vendor Monta recommends enabling OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and applying rate limiting and connection throttling as mitigations.
Related Security News

Vulnerability Backlogs Rooted in Asset Ownership Gaps, Not Detection Shortfalls
A recent Dark Reading article argues that organizations struggling with vulnerability backlogs do not need enhanced scanning tools. Instead, the piece emphasizes that the core problem lies in identifying asset owners, establishing remediation authority, and planning remediation capacity. The analysis suggests that without clear ownership structures, even the best detection tools will produce unmanageable backlogs.




