CVE-2026-69658

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.

  • Published Aug 28, 2026
  • CVSS 9.3 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-69658 at the National Vulnerability Database