Gardyn Security Incident

CISA Advisory ICSA-26-055-03

All ten CVEs in CISA advisory ICSA-26-055-03, as updated April 2, 2026 (Update A). Each entry links to the canonical NVD record, MITRE CVE record, and per-CVE researcher repository where available.

The advisory

AdvisoryCISA ICSA-26-055-03
Initial publicationFebruary 24, 2026 (4 CVEs)
Update AApril 2, 2026 (10 CVEs)
VendorGardyn Inc.
Affected productsGardyn Home Kit (Models 1.0, 2.0, 3.0, 4.0), Gardyn Studio (Models 1.0, 2.0)
Affected versionsMobile App <2.11.0; Cloud API <2.12.2026; Home Kit Firmware <master.622
SectorFood and Agriculture (CISA classification)
Registered devices (per researcher repository)138,160+
User records (per CVE-2026-28766)134,215
ResearcherMichael Groberman
CoordinatorCERT/CC (parent case VU#653116) and CISA
Status per CISA Update AAll ten CVEs remediated

The ten CVEs

CVETitleSeverity
CVE-2026-28766Missing Authentication: User Account EndpointCritical (9.3)
CVE-2025-1242Use of Hard-coded CredentialsCritical (9.1)
CVE-2025-29631OS Command InjectionCritical (9.1)
CVE-2026-25197Authorization Bypass via User-Controlled Key (IDOR)Critical (9.1)
CVE-2025-10681Hardcoded Azure Blob Storage Account KeyHigh (8.6)
CVE-2025-29628Cleartext Transmission of Sensitive InformationHigh (8.3)
CVE-2025-29629Use of Default CredentialsHigh (8.3)
CVE-2026-32646Missing Authentication: Admin Device ManagementHigh (7.5)
CVE-2026-28767Missing Authentication: Admin NotificationsMedium (5.3)
CVE-2026-32662Active Debug Code in ProductionMedium (5.3)

Attack chains documented in the researcher’s repository

Per the researcher’s repository, two attack chains are documented combining individual CVEs:

Disclosure timeline

Per the researcher’s coordinated-disclosure repository, initial vendor outreach was on October 14, 2025; CERT/CC was engaged on December 11, 2025. CISA published the initial advisory on February 24, 2026 with four CVEs and Update A on April 2, 2026 expanding to ten CVEs. See the full timeline and the coordinated disclosure process.

Primary sources