CVE-2026-86520

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

  • Published Sep 18, 2026
  • CVSS 8.7 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-86520 at the National Vulnerability Database