Hello readers!

This week, we’re looking at the state of IoT security in 2026 so far, autonomous connectivity, designing for disconnection, and more!

Half of 2026’s Worst IoT Exploits Were Already Out in the Open

Forescout, a cybersecurity firm that tracks device exposure across enterprise and industrial networks, counted 37,137 new vulnerabilities in the first half of 2026 — a 51 percent jump over the same period last year, with 55 percent rated high or critical severity and 54 already caught being exploited as zero-days. Forty-six percent of the vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog this year had been publicly disclosed before 2026 even started. Attackers are not, in the main, racing to weaponize the newest flaw. They're working through a backlog — cameras, industrial gateways, badge readers, sensors — running software nobody got around to patching, on networks nobody fully mapped. That gap between known and fixed, not known and unknown, is where most of 2026's connected-device exploitation is happening, and for a large share of devices it has stayed open for years.

That backlog is exactly what a new pair of EU laws is aimed at closing, and the timeline is tighter than most IoT teams have absorbed. The Cyber Resilience Act's first hard deadline lands on September 11, 2026 — manufacturers must start reporting actively exploited vulnerabilities and severe incidents within 24 hours, and the obligation reaches products already sitting in the field, not just new ones. NIS2, already in force, adds ten minimum security measures across 18 sectors and makes management boards personally accountable for approving them. Together the two laws put a legal clock on something Forescout's data already shows: a device counts as secure only when someone can prove, on a short deadline, that they knew about a problem and acted — not simply because a patch exists somewhere upstream.

The backlog exists for structural reasons, not because vendors are careless. A GSMA survey cited by eSIM security firm Kigen found only 22 percent of organizations call themselves highly prepared for the CRA, able to push over-the-air updates and maintain the process behind them. Another 26 percent can push updates but haven't built compliant manufacturing processes around them. The remaining half splits between teams whose field devices lack the memory and processing power to support years of patches, and teams with no remote update capability at all. A smart meter buried in a field or a sensor on a shipping container was never built the way a laptop was — deployed for a decade, often unreachable, running on a battery budget that can't absorb a full security stack. Updating that fleet is a hardware and logistics problem before it's a software one.

Two different fixes are converging on the same deadline. On the hardware side, eSIM technology is being repositioned as more than a connectivity swap — its secure element can work as a hardware root of trust, letting a device authenticate itself and receive verified updates with proof of delivery, which is the evidence trail regulators are asking for. On the network side, the compensating control for a device that can't be patched yet follows the Zero Trust model security teams use elsewhere: segment it, restrict what it can reach, watch its traffic, log every session a contractor opens on it. Neither fix retires the backlog alone. A root of trust doesn't help a ten-year-old camera that never had one, and segmentation doesn't turn an unpatched flaw into a patched one. What both do is shrink the damage a known-but-unfixed device can cause while replacement happens on its own slower schedule.

The practical move this month is unglamorous: build the device inventory before the report is due, not after. Know which devices exist, which ones can take an update and which ones can't, and which regulatory bucket each falls into — NIS2, the CRA, or both. September 11 is closer than December 2027, and it applies to hardware already deployed, not just what ships next quarter. Fix detection before fixing everything else; a 24-hour reporting clock means nothing if an incident surfaces a week late. Most of this work doesn't wait on a vendor — it's a count of a device population that, per Forescout's numbers, has been running exploitable software longer than most teams would like to admit. Doing that count now is cheaper than doing it during an incident response call in October.

📖 Top Articles

Every connectivity platform claims to be automated. But automation isn’t the same as autonomy.

At the edge, the network isn't slow — sometimes it's simply gone. Here are the data patterns that assume disconnection as a normal operating condition, not a failure.

What happens to IoT data after it leaves the broker — and how to think about the messaging layer between the edge and everything else.

🔥 Rapid Fire

🎙 The IoT For All Podcast

In this episode of the IoT For All Podcast, Wienke Giezeman, CEO and co-founder of The Things Industries, joins Ryan Chacon to discuss how IoT is finally delivering what it promised ten years ago. The conversation covers what changed technically and commercially, the ROI of IoT, why deployments failed in the early days, criticism of IoT, what companies still get wrong about LoRaWAN, and The Things Conference 2026.

Partner Spotlight

Kajeet provides optimized IoT connectivity, software, and hardware solutions that deliver safe, dependable, and controlled internet connectivity to students, enterprises, state and local governments, and IoT solution providers. Kajeet is the only managed IoT connectivity services provider in the industry to offer a scalable IoT management platform, SentinelÒ, that includes mobile policy and usage control, advanced analytics and reporting, usage processing control, service provisioning, customer care management, and application integrations.

Interested in becoming an IoT For All Partner? Reach out here!

📚 Ebooks & White Papers

By KPMG

How Edge AI and Physical AI are critical enablers of faster, more autonomous, and more efficient real-world operations.

NATS JetStream and Apache Kafka — the architectural differences that matter, and where each one wins.

📆 Events & Webinars

Hosted by TechEx Events

IoT Tech Expo Europe returns to Amsterdam as Industrial AI and Edge Intelligence reshape connected industry.

20% Discount Code: MP20

Hosted by Com4

Join Com4 for a live webinar on how reliable IoT connectivity gives energy and utilities companies real time asset visibility.

Keep Reading