CVE-2026-22616Active Exploitation(eaton / intelligent_power_protector)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch eaton intelligent_power_protector systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton download centre.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • intelligent_power_protector

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
intelligent_power_protector

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-16: 3Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 304-16
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • NerdieNews@NewsNerdie
    Active Exploitation

    Eaton Intelligent Power Protector CVE-2026-22616 is under active exploitation—attackers can brute force web authentication, compromising systems globally. Patch now; the vulnerability bypasses authentication safeguards. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #Adobe https://t.co/hn9Adq8PDA

    Post summary

    The tweet says CVE-2026-22616 is actively being exploited through brute‑force authentication attacks worldwide and urges users to apply the available patch.

    0000035
    55 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-22616 Brute Force Authentication Vulnerability in Eaton Intelligent Power Protector Web Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22616

    Post summary

    The tweet references CVE-2026-22616, noting a brute‑force authentication issue in Eaton’s Intelligent Power Protector web interface, but offers limited further detail.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22616 Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting contro… https://www.cve.org/CVERecord?id=CVE-2026-22616

    Post summary

    The CVE record notes a lack of authentication rate limiting in Eaton IPP, enabling repeated login attempts, but provides no PoC, exploit, or patch details, nor evidence of active exploitation.

    0000067
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeatonintelligent_power_protector---

Explore more