Rently has patched this vulnerability in late June 2026. Users should update to the latest version of Rently Smart Home. CISA recommends minimizing network exposure for control system devices, ensuring they are not accessible from the internet, locating control system networks behind firewalls isolated from business networks, and using updated VPNs for remote access.
Quick answers
What is CVE-2026-75960?
Rently has patched this vulnerability in late June 2026. Users should update to the latest version of Rently Smart Home. CISA recommends minimizing network exposure for control system devices, ensuring they are not accessible from the internet, locating control system networks behind firewalls isolated from business networks, and using updated VPNs for remote access.
How severe is CVE-2026-75960?
high, CVSS 8.7
Is CVE-2026-75960 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-75960 be mitigated?
Rently has patched this vulnerability in late June 2026. Users should update to the latest version of Rently Smart Home. CISA recommends minimizing network exposure for control system devices, ensuring they are not accessible from the internet, locating control system networks behind firewalls isolated from business networks, and using updated VPNs for remote access.
CVSS
8.7
Vendor
Rently
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Rently Smart Home
Mitigation
Rently has patched this vulnerability in late June 2026. Users should update to the latest version of Rently Smart Home. CISA recommends minimizing network exposure for control system devices, ensuring they are not accessible from the internet, locating control system networks behind firewalls isolated from business networks, and using updated VPNs for remote access.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding a vulnerability in Rently Smart Home software. Successful exploitation of CVE-2026-75960 could allow an attacker to retrieve sensitive authentication credentials, including the Master Pin, thereby overriding standard user permissions. The flaw stems from insufficiently protected credentials within the affected software versions. Rently has released a patch in late June 2026; no user action is required for those running updated versions. The vulnerability carries CVSS v3 base scores of 8.1 and CVSS v4 base scores of 8.7, both rated HIGH. CISA notes no known public exploitation at this time but recommends defensive measures to minimize risk.