Skip to content
Critical Vulnerabilities in EnOcean SmartServer Expose Building Management Systems to Attacks

Critical Vulnerabilities in EnOcean SmartServer Expose Building Management Systems to Attacks

First seen 30 Apr 2026, 13:56 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •May 1, 2026 at 13:35 UTC
  • •CVE-2026-20761 allows remote code execution on EnOcean devices without prior authentication.
  • •CVE-2026-22885 can leak memory and bypass ASLR protections, increasing attack vectors.
  • •EnOcean recommends immediate software updates to mitigate these vulnerabilities.

Two critical vulnerabilities, CVE-2026-20761 and CVE-2026-22885, were discovered in EnOcean's SmartServer IoT platform, affecting versions 4.60.009 and earlier. CVE-2026-20761 allows remote attackers to execute arbitrary commands on devices via crafted LON IP-852 messages, with a CVSS score of 8.1. CVE-2026-22885 enables attackers to bypass ASLR protections and leak memory, scoring 3.7 on the CVSS scale. Successful exploitation of these vulnerabilities could grant attackers full control over building management systems and legacy i.LON devices, impacting critical infrastructure such as HVAC and power systems. EnOcean has released mitigations and recommends users update to SmartServer 4.6 Update 2 (v4.60.023). The vulnerabilities were published on February 20, 2026, and pose significant risks to facilities using affected systems. The research highlights the dangers of legacy protocols being retrofitted for modern IoT applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 160d ago How this analysis works

Timeline

2026-02-20
CVE-2026-20761 and CVE-2026-22885 published
2026-04-30
Claroty reports on vulnerabilities and recommends updates
2026-04-30
EnOcean issues mitigations for identified vulnerabilities

More articles in this cluster (3)

Following this threat?

Track EnOcean and CVE-2026-20761 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed