The number and severity of CVEs published that impact products developed by Yarbo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7415CRITICAL The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-7414CRITICAL Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and can | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-7413CRITICAL A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is | May 7, 2026 | 9.8 | 36 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yarbo.
Media articles that mention a CVE ID that affects a product developed by Yarbo — matched by CVE ID, not by vendor name.