Frequency
3
occurrences
First Seen
April 30, 2026
Last Seen
April 30, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two critical vulnerabilities, CVE-2026-20761 and CVE-2026-22885, were discovered in EnOcean's SmartServer IoT platform, affecting versions 4.60.009 and earlier. CVE-2026-20761 allows remote attackers to execute arbitrary commands on devices via crafted LON IP-852 messages, with a CVSS score of 8.1....
Team82 has reported two vulnerabilities, CVE-2026-20761 and CVE-2026-22885, both published on 2026-02-20. The vulnerabilities affect various products and services, although specific systems were not detailed in the articles. Team82 emphasizes its commitment to coordinated disclosure, inviting vendor...
Public Exploits
Checking GitHub for proof-of-concept code…
Related Clusters (2)
Related Entities
Zero-day ExploitEchelonEnOceanCVE-2026-20761CWE-78 - OS Command InjectionCWE-200 - Exposure of Sensitive InformationCWE-287 - Improper AuthenticationCWE-120 - Classic Buffer OverflowCWE-20 - Improper Input ValidationCWE-269 - Improper Privilege ManagementManufacturingT1068 - Exploitation for Privilege Escalation