The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Commercial Real Estate
Breach intelligence, attack campaigns, and threat reports targeting the Commercial Real Estate sector.
Explore Other Sectors
Commercial Real Estate Threat Reports
Critical Siemens Siveillance Control Vulnerability Exposes Industrial Infrastructure to Root-Level Compromise
A critical vulnerability (CVE-2026-50093) with CVSS score 9.0 was discovered in Siemens Siveillance Control and Siveillance Control Pro systems, affecting the Open Interface Services (OIS) web module. The vulnerability allows attackers to upload arbitrary files to the server, potentially leading to unauthorized root-level access and complete system compromise. Multiple versions of Siveillance Control V3.0, V4.0, and Pro editions are affected, with patches now available from Siemens. The vulnerability impacts critical infrastructure sectors including critical manufacturing, communications, and commercial facilities worldwide. This incident highlights the growing threat to industrial control systems and critical infrastructure, particularly as nation-state actors increasingly target OT environments. With the rise of hybrid IT/OT networks and remote access requirements, vulnerabilities in surveillance and control systems present expanded attack surfaces for sophisticated threat actors seeking to disrupt industrial operations.
2 days ago
Kill Chain
Critical Code Execution Flaw Exposes Siemens Building Automation Systems
A critical Client Code Execution vulnerability (CVE-2026-34223) has been discovered in Siemens Desigo CC building automation systems, affecting versions 6 and 7 worldwide. The vulnerability allows attackers to execute arbitrary code on client devices through maliciously crafted graphics documents containing embedded scripts. When users open compromised graphics files, the embedded scripts execute on the client application, enabling attackers to write arbitrary files to the operating system and potentially achieve lateral movement within industrial networks. With a CVSS score of 8.2, this vulnerability poses significant risk to critical manufacturing and commercial facilities globally. This incident highlights the growing threat to industrial control systems and building automation platforms, where code injection vulnerabilities can provide attackers with deep access to critical infrastructure operations and sensitive industrial environments.
2 days ago
Kill Chain
CareCam CM2507 IP Cameras: Seven Critical Vulnerabilities Expose Enterprise Networks
The CareCam CM2507 IP camera contains seven critical vulnerabilities (CVE-2026-88259 through CVE-2026-81321) that collectively allow complete device compromise. These flaws include missing authentication for video streaming, empty passwords in ONVIF services, cleartext credential storage, weak password hashing, and unauthorized script execution from removable media. Attackers can exploit these vulnerabilities to access live video feeds, extract stored credentials, execute arbitrary code, and pivot to connected networks. The vendor has not responded to CISA's coordination attempts, leaving deployed devices unpatched. This incident highlights the persistent security challenges in IoT devices deployed across commercial facilities worldwide, particularly as organizations increasingly rely on IP cameras for security monitoring while threat actors actively target poorly secured IoT infrastructure for initial access and lateral movement.
1 week ago
Kill Chain
Six Critical Vulnerabilities Expose Digital Watchdog Surveillance Systems to Complete Compromise
In September 2026, CISA disclosed six critical vulnerabilities in Digital Watchdog VMAX DVR and NVR surveillance systems affecting all product versions worldwide. The vulnerabilities include authentication bypass (CVE-2026-68953), hard-coded credentials (CVE-2026-66890, CVE-2026-68950), missing authentication for critical functions (CVE-2026-68070), missing authorization (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, allowing attackers to view surveillance footage, alter configurations, and use devices as network pivot points with root-level access. This disclosure highlights the growing security risks in IoT surveillance infrastructure, particularly as organizations increasingly deploy connected security devices without proper hardening. The vulnerabilities demonstrate classic IoT security failures that enable lateral movement within critical infrastructure networks.
1 week ago
Kill Chain
CareCam Pro IP Cameras Expose Critical Bootloader Vulnerability CVE-2026-85083
CISA disclosed CVE-2026-85083, a critical vulnerability in CareCam Pro IP cameras (model ANJIA AJL33PC0801) that exposes hard-coded credentials in the bootloader authentication system. Attackers with physical access can exploit this weakness to gain privileged bootloader access, enabling unauthorized firmware modification and complete device compromise. The vulnerability affects devices deployed worldwide across commercial facilities, with CareCam reportedly unresponsive to coordination efforts from CISA. This incident highlights the persistent security challenges in IoT infrastructure where manufacturers continue to implement insecure authentication mechanisms. As organizations increasingly rely on IP cameras for security monitoring and operational visibility, such fundamental design flaws create significant attack surface expansion and compliance risks.
2 weeks ago
Kill Chain
Critical Rently Smart Home Vulnerability Exposes IoT Access Control Risks
In August 2026, CISA published advisory ICSA-26-237-01 detailing a critical vulnerability (CVE-2026-75960) in Rently Smart Home systems version 20.1.0 and prior. The vulnerability, classified as Insufficiently Protected Credentials with a CVSS score of 8.1, allows attackers to retrieve pins including the Master Pin and override standard user permissions. The flaw affects smart home access control systems deployed across commercial facilities in the United States and India, potentially compromising physical security for properties using Rently's keyless entry solutions. Rently patched the vulnerability in late June 2026, requiring no user action for remediation. This incident highlights the growing security risks in IoT and smart building infrastructure as organizations increasingly adopt connected access control systems. The vulnerability underscores critical gaps in credential protection mechanisms that could enable unauthorized physical access to commercial and residential properties.
4 weeks ago
Kill Chain
Critical Vulnerability in Siemens Siveillance Video Management Servers: CVE-2026-3014
In August 2026, Siemens disclosed a critical vulnerability (CVE-2026-3014) in its Siveillance Video Management Servers, which could allow authenticated users with edit permissions to execute arbitrary code within the Management Server Service. This vulnerability affects versions V2023 R3 prior to V23.3.27, V2024 R1 prior to V24.1.16, and V2025 prior to V25.1.15. Siemens has released patches to address this issue and strongly recommends users update to the latest versions to mitigate potential risks. This incident underscores the ongoing challenges in securing critical infrastructure software, highlighting the importance of timely vulnerability management and the need for organizations to stay vigilant against potential exploitation of such vulnerabilities.
1 month ago
Kill Chain
Critical Vulnerabilities in Johnson Controls' Airwall: CVE-2026-64887 and CVE-2026-34492
In August 2026, Johnson Controls Inc. disclosed two critical vulnerabilities in their Airwall product, identified as CVE-2026-64887 and CVE-2026-34492. CVE-2026-64887 involves the use of a hard-coded cryptographic key, potentially allowing attackers to decrypt sensitive data across all installations. CVE-2026-34492 is an arbitrary file read vulnerability, enabling unauthorized access to system files. Both vulnerabilities affect Airwall versions up to and including 4.0.4. Johnson Controls has released patches in version 4.1.0 to address these issues. The disclosure underscores the persistent risks associated with hard-coded credentials and inadequate input validation in critical infrastructure systems. Organizations are urged to apply the provided patches promptly and review their security practices to prevent similar vulnerabilities.
1 month ago
Kill Chain
Critical Command Injection Vulnerability in Johnson Controls Metasys (CVE-2025-26385)
In January 2026, a critical command injection vulnerability (CVE-2025-26385) was identified in Johnson Controls' Metasys building automation system. This flaw allowed unauthenticated remote attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of affected systems. The vulnerability impacted multiple Metasys components, including the Application and Data Server (ADS), Extended Application and Data Server (ADX), and various tools integrated with SQL Express, across versions 12.0 through 14.1. Johnson Controls promptly released patches and provided mitigation strategies to address the issue. This incident underscores the importance of securing building automation systems, especially as they become increasingly interconnected. Organizations are urged to apply the latest patches, follow vendor-recommended hardening guidelines, and implement network segmentation to protect critical infrastructure from similar vulnerabilities.
1 month ago
Kill Chain
Critical DoS Vulnerability in Siemens Desigo Controllers (CVE-2026-59693)
In August 2026, Siemens identified a denial-of-service (DoS) vulnerability in its Desigo DXR and PXC controllers, designated as CVE-2026-59693. This flaw allows attackers to send malformed BACnet packets, causing the devices to become unresponsive to BACnet queries. Recovery necessitates a device reset or reboot to restore normal functionality. Siemens has released updated firmware versions to address this issue and recommends that users update their devices promptly. This incident underscores the critical importance of securing building automation systems against network-based attacks. As these systems are integral to various critical infrastructure sectors, including commercial facilities, energy, healthcare, and transportation, ensuring their resilience against such vulnerabilities is paramount to maintaining operational continuity and safety.
1 month ago
Kill Chain
Critical Vulnerability in Johnson Controls TL280 Devices: CVE-2026-27871
In August 2026, a critical vulnerability (CVE-2026-27871) was identified in Johnson Controls' TL280 devices, affecting versions prior to 5.63. This flaw involves the use of a broken or risky cryptographic algorithm, potentially allowing unauthorized access to sensitive information. The vulnerability impacts sectors such as Critical Manufacturing, Commercial Facilities, Government Services, Transportation Systems, and Energy, with deployments worldwide. Johnson Controls has released firmware update 5.63 to address this issue and recommends restricting network access to trusted management VLANs, monitoring device access logs, rotating shared credentials, implementing network segmentation, and using secure remote access methods like VPNs. ([johnsoncontrols.com](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories?utm_source=openai)) The discovery of CVE-2026-27871 underscores the ongoing challenges in securing industrial control systems against evolving cyber threats. Organizations are urged to promptly apply the recommended mitigations and stay vigilant against potential exploitation attempts targeting this vulnerability.
1 month ago
Kill Chain
Critical Vulnerabilities Disclosed in Johnson Controls OpenBlue Employee Software
In July 2026, Johnson Controls disclosed multiple vulnerabilities in its OpenBlue Employee (FMS Employee) software, versions up to V2025.3.1. These vulnerabilities include unrestricted file uploads (CVE-2026-21662), stored cross-site scripting (CVE-2026-34495), and HTML injection (CVE-2026-34497). Exploitation could allow attackers to upload malicious files, execute scripts, or inject arbitrary HTML content, potentially compromising system integrity and user data. The disclosure underscores the critical need for organizations to promptly apply security patches and implement robust web application security measures. As cyber threats targeting web applications continue to rise, maintaining vigilance and proactive defense strategies are essential to safeguard sensitive information and maintain operational continuity.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports