Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50089: CWE-601 URL redirection to untrusted site ('open redirect') in Aqara Aqara IAM/SSO GatewayCVE-2026-50089 0 The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1 Medium), which can be used to set up a phishing attack. Join the discussion | CVE Database V5 | 06/12/2026, 15:02:02 UTC Added: 06/12/2026, 15:39:37 UTC |
CVE-2026-50085: CWE-306 Missing authentication for critical function in Aqara Board serviceCVE-2026-50085 0 The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices. Join the discussion | CVE Database V5 | 06/12/2026, 15:01:13 UTC Added: 06/12/2026, 15:39:37 UTC |
CVE-2026-50083: CWE-798 Use of Hard-coded Credentials in Aqara Aquara IAM/SSO GatewayCVE-2026-50083 0 The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices. Join the discussion | CVE Database V5 | 06/12/2026, 15:00:49 UTC Added: 06/12/2026, 15:39:34 UTC |
Showing 1 to 3 of 3 results