Commercial-facilities Sector
2 articles covering commercial-facilities OT/ICS security
Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and Mitigation
CISA published ICSA-26-204-01 on August 11, 2026, disclosing CVE-2026-21655, a remotely exploitable code execution vulnerability in Johnson Controls C·CURE 9000 physical access control systems. With a CVSS score of 9.8 and no authentication required, the flaw affects C·CURE 9000 versions prior to 3.0.3 deployed in enterprise and critical infrastructure physical security management. This advisory covers the vulnerability details, affected versions, exploitation risk in OT-adjacent environments, and recommended mitigations.
Building Automation System Security: BACnet, BMS Hardening, and the OT-IT Convergence Risk
Building automation systems control HVAC, lighting, access control, and fire suppression across commercial and industrial facilities. As BAS deployments converge with IP networks, legacy protocols like BACnet and Modbus are now internet-adjacent — with predictable results for attack surface.