CVE-2026-8374: Switchbot Lock Series App
High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.
Affected products
- Switchbot Lock Series App: up to and including 9.2.6
- Switchbot Lock Series Keypad: up to and including 2.7
- Switchbot Lock Series Lock: up to and including 3.4
Published 2026-10-09. Last modified 2026-10-09.