CVE-2026-3465Disclosure

LOWCVSS 1.3 · LOW

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. There is ongoing doubt regarding the real existence of this vulnerability. The vendor disagrees with the conclusion of the finding: "The described vulnerability fails to prove its feasibility or exploitability by attackers. The issue essentially does not constitute a security vulnerability, aligning more closely with abnormal product functionality." These considerations are properly reflected within the CVSS vector.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-03); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-03: 4Mentions · 2026-03-04: 1Active Exploitation · 2026-03-04: 1Technical Details · 2026-03-03: 203-0303-04
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-034
Disclosure4
2026-03-041
Active Exploitation1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3465 A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Hand… https://www.cve.org/CVERecord?id=CVE-2026-3465

    Post summary

    A vulnerability (CVE‑2026‑3465) has been identified in the Tuya App and SDK 24.07.11 for Android, affecting an unspecified functionality of the JSON Data Point component. No additional details on exploitation, patches, or technical specifics are provided.

    01010268
    56.6K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Tuya App and SDK (CVE-2026-3465) https://vuldb.com/?ctiid.348536

    Post summary

    The post reports that CVE-2026-3465 is being actively exploited against Tuya App and SDK, with offensive activity identified, but no PoC, patch, or technical details are provided.

    0000094
    2.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3465 - Tuya App/SDK JSON Data Point denial of service Intel Report: https://ift.tt/8JBGl9R

    Post summary

    A new denial‑of‑service vulnerability (CVE‑2026‑3465) affecting Tuya App/SDK JSON data points has been reported, with an Intel report linked for further details.

    0000035
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3465 A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Hand… https://www.cve.org/CVERecord?id=CVE-2026-3465 ----- Traducción: CVE-2026-3465 Se … http://infoflow.cloud`

    Post summary

    A new CVE-2026-3465 affecting Tuya App and SDK 24.07.11 on Android has been identified, but no further details, PoC, or patch information are provided.

    0000031
    55 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3465 Denial of Service Vulnerability in Tuya App and SDK 24.07.11 on Android https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3465

    Post summary

    A Denial of Service vulnerability (CVE-2026-3465) has been disclosed for Tuya App and SDK 24.07.11 on Android, with no PoC, exploit, or patch details provided.

    0000048
    4.0K followersView on X

Explore more