08/31/2026
FYI
Locksmith Industry Brief — August 31, 2026
1. Immediate: Autel KM100 validation begins September 1
Starting tomorrow, supported security functions on the Autel KM100 will require authentication through NASTF’s Secure Data Release Model. This includes supported all-keys-lost, add-key and immobilizer procedures. IM508 and IM608 models will follow in later phases. Autel resource center and NASTF application requirements.
Field action:
Update the KM100 and test VSP login, multifactor authentication and location services before accepting the next security job.
Remember that only one phone can be registered per NASTF account; VPNs and disabled location services can prevent authentication.
Every technician performing the transaction needs their own credential—do not share the owner’s login.
New applications currently require roughly two to three weeks, proof of licensing/employment, two references and qualifying liability insurance. Anyone applying now should arrange a legitimate backup programming workflow during approval.
Continue verifying ID and vehicle authority even though SDRM creates the electronic transaction record.
2. High-severity Rently Smart Home credential exposure
CISA disclosed CVE-2026-75960 on August 25. Rently Smart Home versions 20.1.0 and earlier insufficiently protected stored PINs, potentially allowing a low-privilege account to retrieve the Master PIN and override normal permissions. CISA rates it high severity and reports no known exploitation.
Rently says it patched the vulnerability in late June and requires no user action. CISA advisory and NIST vulnerability record.
For multifamily customers:
Record which properties use Rently and confirm they remain connected to the supported service.
As a prudent precaution—not a vendor requirement—review administrative activity and rotate Master PINs, especially where PINs were reused or broadly distributed.
Check that terminated employees, vendors and former property managers no longer retain accounts or codes.
Explain that replacing the mechanical lock alone would not address a compromised platform-level PIN.
3. Schlage introduces persistent Wi-Fi XE360 locks
On August 25, Allegion announced XE360 with RealSync: persistent Wi-Fi connectivity providing immediate credential changes, remote lock/unlock, real-time events and over-the-air firmware updates without panels, gateways or new cabling. Existing offline XE360 locks can reportedly be upgraded by exchanging their FleX communication module. Allegion claims more than one year of operation on four AA batteries under suggested use.
Brivo will be the first integrated PACS partner, with others to follow; the announcement indicates broader integration was still underway before commercial availability. Allegion announcement.
Practical implications:
Useful candidate for retrofit doors where running cable is expensive.
Before specifying, confirm actual availability, supported PACS, Wi-Fi coverage, firewall requirements, credential formats and ownership of cloud subscriptions.
Put battery replacement, firmware management and loss-of-network behavior into the maintenance agreement.
Treat the one-year battery figure as a manufacturer claim until performance is proven under the site’s traffic and signal conditions.
4. Falcon T Series has been discontinued
Allegion discontinued the Falcon T Series Grade 1 cylindrical lock on August 12 and replaced it with the TM Series. Limited T-Series service parts remain. Allegion product notice and Allegion Knowledge Center.
Field action:
Update estimates, specifications and purchasing templates from T to TM.
Inventory high-use T-Series latches, springs, tailpieces and electrified components while service stock remains available.
Do not promise a blind part-for-part substitution. Verify function, lever, cylinder format, latch/strike, door thickness and electrification before ordering TM replacements.
Flag facilities with large T-Series populations for a controlled transition instead of waiting for obsolete parts to fail.