CVE-2026-50085 - Unauthenticated MQTT command injection in Aqara Board service. CVSS 8.6. Remote device takeover possible when chained with other flaws. No patch available. Monitor and isolate affected systems. #CVE #Aqara #infosec
CVE-2026-50090 is a critical vulnerability (CVSS 9.3) in the Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize).
🔗 CVE-2026-50090 | Aqara | Valters IT Hub
If you're connecting your Aqara devices directly to Home Assistant and are not using the Aqara cloud, then my read on this is that you should be good to go. This is not a vulnerability in the devices themselves but with the Aqara cloud stuff.

La cerradura inteligente Aqara U200 se instala sin taladrar y ofrece múltiples métodos de desbloqueo, incluyendo huella dactilar y NFC. Compatible con Matter y Apple Home, se controla vía la app Aqara Home y cuenta con geovalla para desbloqueo automático.

La cerradura inteligente Aqara U200 se instala sin taladrar y ofrece múltiples métodos de desbloqueo, incluyendo huella dactilar y NFC. Compatible con Matter y Apple Home, se controla vía la app Aqara Home y cuenta con geovalla para desbloqueo automático.
⚙️ Aqara G5 Pro: Top HomeKit Outdoor Camera in 2026?
The Aqara G5 Pro remains a top contender in the HomeKit outdoor camera market, featuring integrated AI and versatile connectivity options.
https://www.byte-pulse.net/article/aqara-g5-pro-top-homekit-outdoor-camera-in-2026