INTELLIGENCE ARCHIVE

smart-buildings

smart-buildings

Is Your Building Exposed to CVE-2026-20761? A 4-Question Self-Audit for EnOcean SmartServer

On 2026-05-16, Claroty's Team82 disclosed CVE-2026-20761 — an unauthenticated remote code execution flaw in EnOcean SmartServer building controllers. An attacker with reachability to the device can execute arbitrary commands as root.

4 min read