CVE-2026-77974
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
- Published Sep 9, 2026
- CVSS 8.5 high
- 0.3% chance of exploitation in the next 30 days (EPSS)