All CVEs
Vulnerability intelligence

CVE-2026-13768

Gardyn Gardyn Home Firmware CWE-798

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.

CVSS Score
10
Critical
EPSS — Exploit Probability
0.7%
Riskier than 49% of all CVEs · checked 2026-09-30
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

2 articles across 2 outlets · first covered Jul 2, 2026 · latest Jul 10, 2026

Coverage timeline

Related CVEs — Gardyn