LIVE · cybersecurity feed
Latest
Archive
CVE Tracker
Report
Ransomware
Vulnerability
Breach
Malware
Nation-state
Phishing
Zero-day
AI
Cloud
Live wire
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
vendor
Aqara
8 CVEs published in the last four months. Exploited flaws first.
Critical
5
High
3
Medium
0
Exploited (KEV)
0
All recent CVEs
CVE
CVSS
Severity
Product
Summary
Published
CVE-2026-50086
10
critical
iam\/sso gateway
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's sign
85d ago
CVE-2026-50084
9.6
critical
cloud production api
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for acc
85d ago
CVE-2026-50090
9.3
critical
cloud oauth authorization endpoint
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypas
85d ago
CVE-2026-50083
9.1
critical
iam\/sso gateway
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of
85d ago
CVE-2026-50091
9.1
critical
home
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so)
85d ago
CVE-2026-50085
8.6
high
board service
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the plat
85d ago
CVE-2026-50088
8.2
high
developer portal
The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test
85d ago
CVE-2026-50087
8.2
high
iam\/sso gateway
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is a
85d ago
Filter the full tracker by Aqara →