CISA Identified Vulnerabilities in Monta Charging Software
The discovered flaws could grant unauthorized administrative control over charging stations globally.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust that technology companies prioritize user security in their software updates?
CISA has issued an advisory for four critical vulnerabilities within the Monta monta.app software platform. These security gaps currently threaten charging infrastructure deployed in energy and transportation sectors worldwide.
Why it matters
The vulnerabilities could allow attackers to execute denial-of-service attacks or gain full administrative control over charging systems. Because these units are integrated into critical utility networks, securing remote access remains a priority for operators.
CISA documented four specific CVE vulnerabilities, labeled CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474. These security gaps enable potential unauthorized administrative access or service disruption.
The players
CISA
The Cybersecurity and Infrastructure Security Agency is a United States federal agency that monitors threats to critical national infrastructure.
Monta
A Netherlands-based software firm that develops management platforms for EV charging stations used in the energy and transportation sectors.
The details
Attackers exploit these vulnerabilities to bypass authentication protocols or flood the system with traffic to force a denial-of-service, a state where a machine or network resource is unavailable to intended users. The software is used to manage charging stations across transportation and energy grids. CISA advises operators to limit direct network exposure of the software and require the use of VPNs—encrypted tunnels that mask internet traffic—for all remote administrative access.
Timeline
- 2026-10-01
CISA released the formal advisory for the Monta software vulnerabilities.
The Tech Race
This vulnerability disclosure reflects a broader, ongoing effort by security agencies to harden the digital infrastructure supporting global electrification. As charging networks scale, they become prominent targets compared to isolated industrial controllers, making the patch lifecycle a critical competitive metric for software providers.
Operators managing charging networks should prioritize restricting network exposure and enforcing VPN use for all remote connections. No public exploitation of these flaws has been reported, but administrators should verify their specific software version against the latest CISA guidance.
The takeaway
The security of charging infrastructure is becoming as critical as the hardware efficiency itself. Stakeholders should monitor official CISA communications for specific patch releases or firmware updates from the vendor.
Further reading
For more on how agencies monitor global infrastructure, see our coverage of Cybersecurity.
Source note: This article includes information reported by Cisa.
Live Poll
Do you trust that technology companies prioritize user security in their software updates?







