Vulnerability intelligence
CVE-2026-13768
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
CVSS Score
10
Critical
EPSS — Exploit Probability
0.6%
Riskier than 45% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered Jul 2, 2026 · latest Jul 10, 2026
Tracked incidents
Coverage timeline
-
Critical flaw in Gardyn IoT Hub lets attackers run code remotelysecurityonline.info · Jul 10, 2026
-
Gardyn IoT Hub bugs expose smart gardens to remote hijackwww.cisa.gov · Jul 2, 2026