
Attackers exploiting CVE-2026-4293 in Kieback & Peter building controllers use session hijacking to escalate privileges, then move laterally across building automation networks. Runtime segmentation can help contain post-compromise activity in OT environments. #OTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/kieback-peter-ddc-building-controllers-cve-2026-4293
Post summary
Attackers are actively exploiting CVE-2026-4293 in Kieback & Peter building controllers, using session hijacking to gain privileged access and lateral movement within the OT environment, underscoring a real‑world threat.

