Security Advisories

Shelly publishes security advisories for vulnerabilities affecting our products and services. This page is the permanent, canonical index of all advisories we have issued. Bookmark this URL — it will not change, even as the format below evolves.

How to use this page

Each advisory has a unique identifier, a short description, a severity rating, and a link to the full advisory (PDF). Advisories are listed with the most recent first.

  • Identifier — e.g. SHEL-2026-001, permanent once assigned
  • Title — short description of the affected product/component and issue
  • Severity — Critical / High / Medium / Low (CVSS-based)
  • Affected products — device models or services in scope
  • Published / Updated — dates
  • Advisory — link to the full PDF

Current advisories

No advisories have been published yet. This section will be updated as advisories are issued.

Reporting a vulnerability

If you believe you have discovered a security vulnerability in a Shelly product or service, please report it to security@shelly.com. For the report form and our Vulnerability Disclosure Policy, see Security Information and Vulnerability Reporting.