CVE-2026-8374None▾ SunlitMisuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-53960Medium· 5.9When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm)
CVE-2025-68833Medium· 5.3HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
CVE-2025-30156High· 8.9Ceph is an open-source distributed storage platform providing object, block, and file storage
CVE-2026-50303Medium· 5.5Windows Key Guard Security Feature Bypass Vulnerability
CVE-2026-59651High· 7.5In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key
CVE-2026-5087High· 7.5PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the /dev/urandom device directly