CISA Identified Vulnerabilities in Monta Software

The cybersecurity agency discovered four flaws that could allow unauthorized control of EV charging stations.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of an electric vehicle charging station pedestal connected to an industrial junction box, representing energy infrastructure security.
The Cybersecurity and Infrastructure Security Agency warned of four vulnerabilities in Monta software that could allow remote administrative control of EV charging stations. AI Illustration. Upload story photo >

Live Poll

Do you trust that technology companies prioritize user security in their software updates?

CISA has issued an advisory regarding four newly identified vulnerabilities in the Monta monta.app software. If exploited, these flaws could grant attackers administrative control over charging stations or result in denial-of-service attacks.

Why it matters

The software is widely used across the energy and transportation sectors worldwide, creating significant security risks for infrastructure. Protecting these systems is critical to preventing unauthorized remote access to charging networks.

The four specific vulnerabilities identified by CISA are CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474. These security gaps specifically threaten the administrative integrity of EV charging hardware.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is a United States federal agency tasked with protecting national infrastructure from cyber threats.

Monta

Monta is a Netherlands-based technology company that provides software solutions for the global energy and transportation sectors.

The details

Attackers could potentially exploit these weaknesses to take full administrative control of charging hardware or disrupt service entirely through denial-of-service attacks. CISA recommends that operators minimize network exposure and utilize VPNs to secure remote access to the affected units.

Timeline

  1. October 1, 2026: CISA officially released the security advisory for the Monta monta.app software.

The Tech Race

This vulnerability disclosure follows the standard notification procedures established by the CISA Cybersecurity Advisory framework. It highlights the growing security burden on software platforms as critical infrastructure systems move toward centralized, internet-connected management.

Operators and businesses utilizing Monta software should immediately restrict network exposure to maintain station security. Using a VPN for all necessary remote administrative tasks is currently the most effective way to prevent unauthorized access to these charging networks.

The takeaway

Securing internet-connected hardware remains a high priority as vulnerabilities in management software can have immediate real-world consequences for infrastructure. Operators should prioritize network segmentation and secure remote access protocols to mitigate potential exploitation.

Further reading

For additional insights on protecting industrial systems, visit the Cybersecurity section.

Source note: This article includes information reported by Cisa.

Live Poll

Do you trust that technology companies prioritize user security in their software updates?