LIVE · cybersecurity feed
Live wire
vendor

Aqara

8 CVEs published in the last four months. Exploited flaws first.

Critical5
High3
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-5008610criticaliam\/sso gatewayThe Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's sign85d ago
CVE-2026-500849.6criticalcloud production apiThe Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for acc85d ago
CVE-2026-500909.3criticalcloud oauth authorization endpointThe Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypas85d ago
CVE-2026-500839.1criticaliam\/sso gatewayThe Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of85d ago
CVE-2026-500919.1criticalhomeAqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) 85d ago
CVE-2026-500858.6highboard serviceThe Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the plat85d ago
CVE-2026-500888.2highdeveloper portalThe Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test85d ago
CVE-2026-500878.2highiam\/sso gatewayThe Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is a85d ago

Filter the full tracker by Aqara