PatchSiren

MrSteam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MrSteam CVE published 2026-09-24

CVE-2026-95699

CVE-2026-95699 is a high-severity vulnerability in the iSteamX mobile application. Prior to 9/18/2026, the application's AWS policy could grant authenticated users access to wildcard MQTT topics, potentially exposing other users' device data and allowing attackers to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device [truncated]