Vulnerability record

CVE-2026-93291

Severity: CriticalExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-93291 scored CVSS 9.3

    Basis: NIST National Vulnerability Database

  2. Disclosed

    Eufy Omni C20, Omni X10 Pro

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

Severity: CriticalAction: Patch

Eufy Omni C20, Omni X10 Pro

Patch

Apply the vendor's security update for the affected products.

References

  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02