Connected devicesAn ordinary iSteamX account could use wildcard MQTT permissions to read other customers’ telemetry and start or stop their steam generators.Vendor countermeasures took effect September 18, but the public record gives no fixed version identifiers.SourcesResearchhttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-267-01.jsonResearchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95699.jsonSecondaryCVE-2026-95699 - GitHub Advisory DatabaseCopy linkShare this findingEmailHacker NewsRedditMastodonBlueskyXLinkedInFacebookCopy link