Skip to content

Eaton vulnerabilities

3 CVEs tracked

In our reporting, Eaton appears primarily in the context of critical vulnerabilities affecting its Tripp Lite series PADM firmware. Three main events were recorded this month: an authentication bypass (CVE-2026-22620) and two privilege escalation flaws (CVE-2026-22621, CVE-2026-22622). CVE-2026-22620 poses the highest risk, as it allows an unauthenticated remote attacker to gain privileged access. Defenders should prioritize firmware updates for Eaton Tripp Lite devices and restrict network-level access, especially to mitigate CVE-2026-22620.

Azərbaycanca: Hesabatlarımızda Eaton, əsasən Tripp Lite seriyası PADM proqram təminatı ilə bağlı kritik zəifliklər kontekstində görünür. Bu ay üç əsas hadisə qeydə alınıb: autentifikasiyanın bypass edilməsi (CVE-2026-22620) və iki imtiyaz yüksəltmə qüsuru (CVE-2026-22621, CVE-2026-22622). CVE-2026-22620 uzaqdan, autentifikasiya olunmamış hücumçuya imtiyazlı giriş imkanı yaratdığı üçün ən yüksək riski daşıyır. Müdafiəçilər Eaton Tripp Lite cihazlarının firmware yeniləmələrinə diqqət yetirməli, xüsusilə CVE-2026-22620-dən qorunmaq üçün şəbəkə səviyyəsində girişi məhdudlaşdırmalıdırlar.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Eaton: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.