CVE-2026-95699Critical· 9.6▾ MidnightPrior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' dev…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82964High· 8.8Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…
CVE-2026-92006High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-92034Critical· 9.1Site isolation issue in the Graphics component
CVE-2026-92045Critical· 9.6Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVE-2026-92066Critical· 9.8Sandbox escape in the Profile Backup component
CVE-2026-92068Medium· 5.4Site isolation issue in the Reader Mode component