Every CVE whose affected-product data names Aqara Iam/sso Gateway, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (4)
CVE-2026-50086 — CVSS 10.0 (critical): The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without…
CVE-2026-50083 — CVSS 9.1 (critical): The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of…
CVE-2026-50087 — CVSS 8.2 (high): The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942…
CVE-2026-50089 — CVSS 6.1 (medium): The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted…