CVE-2026-24060Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format used by WebCTRL to receive updates from the PLC can also be sniffed and reverse engineered.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-21)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 1Mentions · 2026-03-21: 3PoC Mentioned / Linked · 2026-03-20: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 303-2003-21
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-213
Disclosure2General1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-24060 Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable inform… https://www.cve.org/CVERecord?id=CVE-2026-24060

    Post summary

    The CVE highlights a lack of encryption for BACnet transmitted data, allowing potential interception and tampering, but no PoC, exploit, or patch details are provided.

    0000095
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24060: CRITICAL] Unencrypted BACnet packets pose a serious threat. Valuable data vulnerable to interception such as File Start Position and File Data can be exposed, risking cyber attacks.#cve,CVE-2026-24060,#cybersecurity https://cvefind.com/CVE-2026-24060

    Post summary

    The tweet announces the critical CVE‑2026‑24060, outlining that unencrypted BACnet packets can expose key file data, but it provides no PoC, exploit, patch, or evidence of active attacks.

    0000048
    604 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-24060 - Critical Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the Fil... https://www.thehackerwire.com/vulnerability/CVE-2026-24060/ https://t.co/JVRFpqwDDG

    Post summary

    The post discloses that CVE-2026-24060 allows attackers to sniff, intercept, and modify unencrypted BACnet traffic, highlighting a confidentiality flaw.

    0000044
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-24060: Automated Logic WebCTRL Premium ... BACnet packets flowing in cleartext means every HVAC command, sensor reading, and PLC update is trivially sniffable—cri... https://zerodaysignal.com/vulnerability/CVE-2026-24060 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-24060, revealing that BACnet traffic is transmitted in cleartext, allowing trivial sniffing, and provides a link to more details.

    0000061
    155 followersView on X

Explore more