
CVE-2026-42209 FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ … https://www.cve.org/CVERecord?id=CVE-2026-42209
Post summary
FlashMQ MQTT broker suffers a crash vulnerability (CVE‑2026‑42209) in versions before 1.26.1 when a remote client with retained publish permission interacts; no PoC, exploit, or patch is disclosed.

