CVE-2026-50209: Acer Connect m6e 5g Firmware

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.

Affected products

  • Acer Connect m6e 5g Firmware: up to and including m6e_ai_1.00.000019

Published 2026-06-04. Last modified 2026-07-22.