SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-77974

HIGH · CVSS 8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to spoof a device and, upon gaining user confirmation, exploit the application to transmit firmware via an unauthenticated and unsigned update channel. This could lead to unauthorized firmware installations, potentially compromising device integrity and security. Organizations utilizing affected products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-77974
Severity
HIGH
CVSS
8
EPSS
0.16%

Original NVD Description

After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.