CISA Identified Vulnerabilities in Monta Charging Software

The discovered flaws could grant unauthorized administrative control over charging stations globally.

Updated on Oct. 1, 2026 in Cybersecurity

Bold flat-color editorial illustration of an industrial electrical transformer cabinet with a red lightning bolt symbol, representing cybersecurity in infrastructure.
CISA issued an advisory for four critical vulnerabilities in the Monta software platform, which manages charging infrastructure across international energy and transportation grids. AI Illustration. Upload story photo >

Live Poll

Do you trust that technology companies prioritize user security in their software updates?

CISA has issued an advisory for four critical vulnerabilities within the Monta monta.app software platform. These security gaps currently threaten charging infrastructure deployed in energy and transportation sectors worldwide.

Why it matters

The vulnerabilities could allow attackers to execute denial-of-service attacks or gain full administrative control over charging systems. Because these units are integrated into critical utility networks, securing remote access remains a priority for operators.

CISA documented four specific CVE vulnerabilities, labeled CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, and CVE-2026-93474. These security gaps enable potential unauthorized administrative access or service disruption.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is a United States federal agency that monitors threats to critical national infrastructure.

Monta

A Netherlands-based software firm that develops management platforms for EV charging stations used in the energy and transportation sectors.

The details

Attackers exploit these vulnerabilities to bypass authentication protocols or flood the system with traffic to force a denial-of-service, a state where a machine or network resource is unavailable to intended users. The software is used to manage charging stations across transportation and energy grids. CISA advises operators to limit direct network exposure of the software and require the use of VPNs—encrypted tunnels that mask internet traffic—for all remote administrative access.

Timeline

  1. 2026-10-01

    CISA released the formal advisory for the Monta software vulnerabilities.

The Tech Race

This vulnerability disclosure reflects a broader, ongoing effort by security agencies to harden the digital infrastructure supporting global electrification. As charging networks scale, they become prominent targets compared to isolated industrial controllers, making the patch lifecycle a critical competitive metric for software providers.

Operators managing charging networks should prioritize restricting network exposure and enforcing VPN use for all remote connections. No public exploitation of these flaws has been reported, but administrators should verify their specific software version against the latest CISA guidance.

The takeaway

The security of charging infrastructure is becoming as critical as the hardware efficiency itself. Stakeholders should monitor official CISA communications for specific patch releases or firmware updates from the vendor.

Further reading

For more on how agencies monitor global infrastructure, see our coverage of Cybersecurity.

Source note: This article includes information reported by Cisa.

Live Poll

Do you trust that technology companies prioritize user security in their software updates?