← Back to home
ICSA-26-055-03  ·  Published 2026-07-02  ·  View on CISA ICS-CERT ↗

Gardyn Home Kit (Update B)

CVSS 9.3 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control edge devices, access cloud-based devices and user information without authentication, and pivot to other edge devices managed in the Gardyn cloud environment.

Remediations

  • Gardyn states that the relevant fixes are included in the latest version of the Gardyn mobile application. Users are required to run a supported version of the Gardyn App on their phone in order to access Gardyn services and devices.
  • The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.
  • Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version.
  • Further information on Gardyn security can be found here: https://mygardyn.com/security/
  • Further customer support can be obtained from Gardyn at: [email protected]

Affected Vendors

Gardyn

Affected Products (4)

Gardyn · Gardyn Home Firmware <master.622
Gardyn · Gardyn Studio Firmware <master.622
Gardyn · Gardyn Mobile Application <2.11.0
Gardyn · Gardyn Cloud API <2.12.2026

Affected Sectors

Food and Agriculture

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more