CVE-2026-20761Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-30)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-20: 2Mentions · 2026-04-30: 3Patch / Workaround · 2026-04-30: 2Technical Details · 2026-02-20: 2Technical Details · 2026-04-30: 302-2004-30
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-202
Disclosure2
2026-04-303
Disclosure1Patch2
Full discourse5 posts
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-20761 (CVSS 8.1) enables pre-auth remote code execution on EnOcean SmartServer IoT platforms via crafted IP-852 timezone packets. Successful exploitation grants root access to BMS controllers. Update to version 4.60.023 immediately. #DFIR_Radar https://t.co/8hQRFRlpPi

    Post summary

    The post announces CVE-2026-20761, a remote code execution flaw on EnOcean SmartServer IoT platforms, and urges users to update to version 4.60.023 immediately.

    10010102
    1.4K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【EnOcean SmartServerの欠陥で、建物管理システムが遠隔侵害可能に】 SecurityWeekによると、Clarotyは EnOcean SmartServer に CVE-2026-22885 と CVE-2026-20761 を発見し、インターネット露出デバイスに対してメモリ保護回避、メモリ漏えい、任意コマンド実行が可能だと報告しました。対象はスマートビル、工場、データセンター向けの building automation ゲートウェイです。 この種の機器は“ITでもOTでもない境界装置”として見逃されがちですが、実際には施設制御、環境制御、保守導線のハブです。Linuxベースのデバイスを root で乗っ取られると、監視・制御・足場化のすべてが危険になります。 ビル管理・工場・データセンター運用では、クラウド接続や公開保守経路を含めて SmartServer の露出確認を急ぐべきです。 #ICS #OTSecurity #BuildingAutomation #EnOcean #RCE #BlueTeam https://www.securityweek.com/enocean-smartserver-flaws-expose-buildings-to-remote-hacking/

    Post summary

    EnOcean SmartServer devices exhibit memory protection bypass, leaks, and arbitrary command execution (CVE‑2026‑22885/20761), enabling remote exploitation of building automation gateways, and security teams should urgently assess exposure and apply vendor fixes.

    00000140
    3.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical flaws CVE-2026-20761 and CVE-2026-22885 in EnOcean SmartServer ≤4.60.009 enable remote takeover of building management systems, fixed in v4.60.023. https://threatcluster.io/cluster/critical-vulnerabilities-in-enocean-smartserver-expose-build-92c87164

    Post summary

    The message announces critical flaws CVE-2026-20761 and CVE-2026-22885 in EnOcean SmartServer, highlights remote takeover risk, and states that a patch (v4.60.023) has fixed the issue.

    0000024
    172 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-20761 - High A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 mes... https://www.thehackerwire.com/vulnerability/CVE-2026-20761/ https://t.co/S2a8r5FbZq

    Post summary

    EnOcean SmartServer IoT versions 4.60.009 and earlier are vulnerable to remote attacks via specially crafted LON IP-852 management messages, with no PoC, patches, or evidence of active exploitation disclosed.

    0000031
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-20761** pertains to a critical security flaw in **EnOcean SmartServer IoT version 4.60.009 and earlier**. The vulnerability allows **remote attackers** to exploit the device via **LON IP-852 management messages**. By sending **specially crafted IP-852 messages**, an attacker can execute **arbitrary operating system commands** on the affected device. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2026-20761

    Post summary

    Alert reports CVE‑2026‑20761 in EnOcean SmartServer enables remote code execution via crafted LON IP‑852 messages. No PoC, exploit, or patch is discussed.

    0000033
    20 followersView on X

Explore more