AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19292

HIGH · CVSS 8.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability exists that allows re-pairing with a legitimate device at a reduced security level, making it easier for attackers to brute-force the Long-Term Key (LTK). This poses a significant risk to the confidentiality and integrity of communications between devices. Organizations utilizing affected products should prioritize addressing this vulnerability to mitigate potential unauthorized access and data breaches.

CVE
CVE-2026-19292
Severity
HIGH
CVSS
8.8
EPSS
0.23%

Original NVD Description

Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.