CVE-2026-76940
The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.
- Published Aug 28, 2026
- CVSS 8.7 high
- 0.5% chance of exploitation in the next 30 days (EPSS)