PatchSiren cyber security CVE debrief
CVE-2026-32662 Gardyn CVE debrief
CVE-2026-32662 concerns Gardyn Home Kit components where development and test API endpoints mirror production functionality. CISA published the advisory on 2026-02-24 and later updated it on 2026-04-02 to add this CVE and refresh affected product and mitigation details. The advisory rates the issue CVSS 3.1 5.3 (Medium) with a low confidentiality impact and no integrity or availability impact.
- Vendor
- Gardyn
- Product
- <master.619
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-24
- Original CVE updated
- 2026-07-02
- Advisory published
- 2026-02-24
- Advisory updated
- 2026-07-02
Who should care
Gardyn customers and operators managing Home Kit or Studio devices, the Gardyn mobile application, and Gardyn Cloud API integrations—especially anyone exposing these services beyond an expected trusted network.
Technical summary
The advisory states that development and test API endpoints are present and mirror production functionality. Affected versions listed in the source include Gardyn Home Firmware prior to master.619, Gardyn Studio Firmware, Gardyn Mobile Application prior to 2.11.0, and Gardyn Cloud API prior to 2.12.2026. CISA’s source uses CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating a network-reachable issue with limited confidentiality impact.
Defensive priority
Medium. Prioritize remediation for any Gardyn deployments that are internet-reachable or that rely on the affected mobile app and cloud API, then verify versions and update paths.
Recommended defensive actions
- Update Gardyn Home and Studio devices to firmware master.622 or later, as recommended by Gardyn.
- Update the Gardyn mobile application to the most recent supported version.
- Check the current Gardyn App and Home firmware versions inside the app.
- Ensure devices have network connectivity so required firmware updates can download automatically.
- If devices are offline, connect them to a working Internet connection and confirm the update completes.
- Use the CISA advisory and Gardyn security guidance to verify the current affected-version scope before and after remediation.
Evidence notes
Source: CISA CSAF advisory ICSA-26-055-03 (published 2026-02-24, updated 2026-04-02). The source text for CVE-2026-32662 says: "Development and test API endpoints are present that mirror production functionality." The advisory’s revision history shows Update A added CVE-2026-32662 and updated mitigations and affected products. The source also provides CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (5.3 Medium).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32662 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32662
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32662 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32662
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-055-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.