Skip to content

// #iot

2 articles

🏛️ Architecture

Azure IoT Central Privilege Escalation via Sensitive Data Exposure — CVSS 9.9

A CVSS 9.9 privilege escalation vulnerability in Azure IoT Central exposes sensitive platform data allowing authenticated low-privilege attackers to gain administrative control. April 2026 Patch Tuesday addressed the flaw — audit IoT Central role assignments and rotate provisioning credentials now.

#azure +4
🏛️ Architecture

CVE-2026-5194: Critical wolfSSL Flaw Enables Certificate Forgery Across 5 Billion Devices

A critical cryptographic validation flaw in wolfSSL, a lightweight TLS library embedded in billions of IoT devices, routers, industrial control systems, and automotive components, allows attackers to present forged X.509 certificates that pass signature verification without a legitimate private key. The vulnerability enables man-in-the-middle attacks and authentication bypass across an enormous installed base. wolfSSL version 5.9.1, released 8 April 2026, provides the fix.

#cve-2026-5194 +5