CVE-2026-49199: Acer Predator Connect w6x Firmware

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

Affected products

  • Acer Predator Connect w6x Firmware: up to and including w6x_gbl_2.00.000005

Published 2026-05-29. Last modified 2026-07-21.