CVE-2026-22620: Eaton Padm

High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.

Affected products

  • Eaton Padm: up to and including 20

Published 2026-07-30. Last modified 2026-07-31.