CVE-2026-93289

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

  • Published Sep 24, 2026
  • CVSS 9.0 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-93289 at the National Vulnerability Database