IT Pro Expert
Search
IT · 30 Jan 2026 · 12 min read

Which KVM over IP in 2026?

KVM Ultimate Buyer’s Guide Updated June 2026 In 2026, the KVM-over-IP landscape has split into two distinct worlds: the Enterprise Titans (Raritan, Aten) and the Open-Source Disruptors (PiKVM, JetKVM, TinyPilot).…

PiKVM v4

In 2026 the KVM-over-IP market has split into two worlds: the enterprise titans (Raritan, Aten) and the open-source disruptors (PiKVM, JetKVM, TinyPilot). Hardware supply has stabilised. Security is the story of the year.

Updated August 2026 · previously June 2026

A wave of independent audits has confirmed that the cheap end of the market is riddled with fundamental flaws — and that even the well-regarded open-source units are not immune. Choosing the right device, and keeping its firmware current, matters more than ever. This is an updated version of our earlier Which KVM Over IP in 2025 article.

Security

Cheap IP-KVMs are a network-wide risk

In March 2026, firmware-security firm Eclypsium published a study of low-cost IP-KVMs and disclosed nine CVEs across four products: the GL.iNet Comet RM-1, the Angeet/Yeeso ES3, the Sipeed NanoKVM and JetKVM. Their conclusion is worth repeating: these are not exotic zero-days. They are the same basic failures — missing firmware-signature validation, no brute-force protection, broken access controls, exposed debug interfaces — that plagued early IoT devices a decade ago.

A KVM gives an attacker BIOS-level access to every machine it controls — and can silently re-infect a host after you rebuild it.

How the main devices stand after the disclosures

  • Angeet / Yeeso ES3Avoid entirely

    This ultra-cheap clone carries a missing-authentication flaw allowing arbitrary code execution, plus an OS command-injection flaw. As of this update, no patch exists.

    CVE-2026-32297 (CVSS 9.8) · CVE-2026-32298 (CVSS 8.8) · no fix available
  • Sipeed NanoKVMNot for production

    The device that kicked off the panic — flagged by SANS Stormcast in December 2025 and given a "Security F" by researchers. Its price and tiny size made it an inconspicuous tool for North Korean IT workers attempting to covertly access US corporate networks, a scheme that prompted the FBI to visit reviewer Jeff Geerling about the devices. The flaws are real: insecure firmware updates, weak password handling, command injection. Development is active — the application has moved through the 2.4.x line as of June 2026 — but the update mechanism, the default routing of DNS through Chinese servers and the phoning home to Sipeed infrastructure remain legitimate concerns.

    CVE-2026-32296 patched in 2.3.1 · app releases continuing through 2.4.x
  • GL.iNet Comet RM-1Patch and watch

    Four CVEs. The UART root-access issue is now fixed in firmware 1.8.2, and the brute-force and provisioning flaws were fixed earlier in 1.8.1. The firmware-authenticity flaw — the device verifies updates by MD5 hash only, which an attacker in the middle can forge — was still without a published fix at the time of writing. Usable if kept fully patched and kept off any path where an attacker could sit between it and the update server.

    Fixed: CVE-2026-32291 (1.8.2), CVE-2026-32292/32293 (1.8.1) · Outstanding: CVE-2026-32290
  • JetKVMFixed quickly

    Shipped with an insufficient firmware-update verification flaw and an insufficient rate-limiting flaw, both fixed in firmware v0.5.4. Releases have continued steadily through the 0.5.x line since, and signed release verification is now part of the firmware. A strong pick provided you run 0.5.4 or later.

    CVE-2026-32294 · CVE-2026-32295 — both fixed in v0.5.4
  • PiKVM V4 & TinyPilotCleanest records

    Neither carried any new 2026 CVEs of note. Both remain highly recommended when placed behind strong access controls rather than on the open internet.

    No notable 2026 disclosures
  • AtenEnterprise, still patch it

    Don't assume FIPS-grade hardware is bulletproof. Positive Technologies disclosed five flaws in Aten switches in July 2025, since patched. Keep firmware current.

    Five flaws disclosed July 2025 — patched
Deployment

How to deploy any IP-KVM safely

Because a compromised KVM is a direct, silent channel to everything it controls, the deployment model matters as much as the brand.

  • Never expose the web panel to the internet. Front it with Zero Trust Network Access — PiKVM V4, JetKVM and TinyPilot all support Tailscale or WireGuard natively.
  • Enforce multi-factor authentication wherever the device supports it.
  • Isolate KVMs on a dedicated management VLAN with no general internet access.
  • Verify you aren't exposed. Use Shodan, or our Network Protection Tester, to confirm the device isn't reachable externally.
  • Monitor traffic to and from the device, and watch the controlled host for tell-tale signs such as unexplained mouse movement.
  • Keep firmware current. Most of the 2026 issues are already patched in current releases.

Thermal monitoring is also maturing: as server densities rise, leading enterprise units from Raritan and Aten now integrate temperature and humidity sensors directly, helping prevent thermal runaway in remote racks.

Top picks

What to buy in 2026

The gold standard

1. PiKVM V4 Plus

The PiKVM continues to dominate the prosumer and mid-market space.

Best for
IT pros, home labs and SMBs.
New for 2026
Fully matured V4 hardware with 4K support at limited fps, and major improvements to mass storage — mounting ISOs roughly three times faster than previous versions.
Security
The cleanest record of any device here, with no notable 2026 CVEs. Pair it with WireGuard or Tailscale.
Price
~$280 / £220.
The high-speed challenger

2. JetKVM

JetKVM remains the easiest "it just works" option, with an incredibly snappy interface — and the April 2026 hardware revision removed both of its long-standing physical complaints.

Best for
Users who want fast setup without Linux tinkering.
New for 2026
A custom ultra-low-latency WebRTC engine, SSH disabled by default, physical-button administrative confirmation, and audio support. Recent firmware adds H.265 with auto-negotiation, MQTT and Home Assistant integration, partial Tailscale support with simplified installation, extra keyboard layouts, factory reset and signed release verification.
Hardware change
New units replace mini-HDMI with a full-size HDMI port, swap soldered eMMC for a microSD card with storage doubling from 16GB to 32GB, and use a smaller 5-pin extension connector in place of RJ-12. A PoE model is now offered, so the separate splitter is no longer required. Existing units and extensions continue to work together as before.
Security
Two flaws disclosed in March 2026 were fixed in v0.5.4. A great choice as long as it's updated.
Price
MSRP rose from $89 to $103 in April 2026 as the component squeeze bit; the PoE version is $119. Reseller listings run higher.
The polished professional

3. TinyPilot Voyager 3

New for early 2026, the Voyager 3 is the most refined commercial KVM-over-IP we've tested.

Best for
Professional out-of-band management, MSPs and multi-user teams.
New for 2026
Combines KVM over IP with a built-in serial console server. TinyPilot is also beta-testing a Central Management System for fleet management of multiple units, which can be self-hosted via Docker.
Security
Designed to run over VPN or Zero Trust overlays, and notably not implicated in the March 2026 disclosures.
Price
~$400 / £340 standard; varies by configuration.
The enterprise workhorse

4. Raritan Dominion KX IV-101

If you are managing a 4K broadcast suite or a mission-critical data centre, this is the only choice.

Best for
4K at 60fps requirements and high-security government or enterprise labs.
New for 2026
Integration with CommandCenter Secure Gateway for centralised management of thousands of units with FIPS 140-2 encryption.
Price
~$1,100 / £850 new.
Comparison

2026 comparison table

Scroll table sideways →
FeaturePiKVM V4 PlusJetKVMTinyPilot Voyager 3Raritan KX IV-101Aten KN8132VNanoKVM (RISC-V)
Max resolution 1920×1200 (4K lab) 1080p @ 60fps 1920×1200 @ 60fps 4K @ 60fps 1920×1200 1080p
Security rating A+ (open source) B+ (fixed in v0.5.4) A (ZTNA-ready) A+ (enterprise) A (FIPS) F (critical risks)
Access tech HTML5 / VNC WebRTC / cloud HTML5 / TLS HTML5 / client HTML5 / Java-free Web panel
Special feature ATX power control Ultra-low latency Serial + 8 users High-motion 4K 32-port density Extremely cheap
Price (approx) £220 £115 £340 £850 £3,500+ £45

Prices are indicative street prices and move with the ongoing memory and storage price surge — JetKVM's own MSRP rose in April 2026, and other vendors are under the same pressure. Treat the figures as ballpark, not quotes.

Watch list

New products and trends

  • GL.iNet Comet X (GL-RM4PE) — now real. Launched on 29 June 2026, this is the four-port unit previously rumoured. It handles up to four hosts from one device at up to 4K/30fps, with PoE, a built-in touchscreen, 64GB of onboard eMMC for preloaded ISOs, and both 10-inch and 19-inch rack brackets. Remote access works over browser, the GL.iNet app, Tailscale, ZeroTier or NetBird, so GoodCloud can be bypassed entirely. Listed at $279.99 on backorder with shipping estimated for late August 2026; firmware 1.9.2 is targeted for August, with two-way video planned for 1.10.0. Worth knowing the underlying GLKVM platform is a PiKVM derivative — and that GL.iNet's outstanding firmware-verification CVE on the RM-1 is a reason to track Comet firmware releases closely.
  • Direct-USB "crash cart" KVMs. A growing class of units that skip the LAN entirely and plug straight into a laptop over USB-C for local hardware maintenance. The Dez KVM Go is remarkable open-source value at $25, running entirely in a browser via Web Serial; the Open Interfaces KVM Go at $120 is the more premium alternative, powered over the USB-C control connection.
  • The JetKVM clone (Arc KVM) — less compelling now. It was anticipated because it mirrored JetKVM's aesthetic and software while adding full-size HDMI and native PoE. JetKVM's own April revision now offers both, so the clone's headline advantages have largely evaporated.
  • Passive VGA adapters (Leaf KVM). Recently crowdfunded on Crowd Supply, notable for a passive VGA adapter that interfaces with legacy servers such as old XServes without consuming an extra USB port for power.
  • BliKVM v4. An open-source, Linux-based PiKVM-family unit with PoE, 4K HDMI loop-out, BIOS/UEFI access and remote power cycling.
  • Aten "Secure" 5K series. Air-gapped hardware designed for military use, physically preventing data leakage between classified and unclassified networks.
Verdict

Final recommendation

  • Home lab: the PiKVM V4 — cleanest security record and best-supported option.
  • Plug-and-play: the JetKVM, still the best performance-to-price ratio. Buy the current hardware revision for full-size HDMI and PoE, and make sure it runs firmware 0.5.4 or later.
  • Professionals and MSPs: the TinyPilot Voyager 3 — multi-user, serial console included, and now offering self-hosted fleet management.
  • Multiple hosts in one rack slot: the new Comet X is the one to watch, once shipping units and the August firmware land.
  • Enterprise: the Raritan KX IV handles high-motion 4K video flawlessly.
  • Avoid: unbranded ultra-cheap clones, especially the Angeet/Yeeso ES3 — and keep the Sipeed NanoKVM out of any professional environment.

Want out-of-band access done properly?

We design and deploy remote management that sits behind proper segmentation, as part of our cyber security and network installation work.

Get in touch