
CVE-2026-32294 JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmwar… https://www.cve.org/CVERecord?id=CVE-2026-32294
Post summary
CVE-2026-32294 discloses that JetKVM versions before 0.5.4 fail to verify firmware authenticity, enabling potential modification by an attacker‑in‑the‑middle or a compromised update server.

