Watchfire Controller Software

Summary

A critical vulnerability, CVE-2026-5846, has been identified in Watchfire Controller Software versions BC550 12.30, BC750 11.33|12.35, BC760 12.38|13.00, and BC760DC 12.39. Exploitation could allow a malicious user to deliver malicious firmware, update the controller, and gain full control.

IFF Assessment

FOE

The discovery of a critical vulnerability that allows for full control of industrial controllers poses a significant threat to operational technology environments.

Severity

5.7 Medium

Defender Context

This vulnerability impacts critical infrastructure sectors, including commercial facilities, manufacturing, healthcare, and financial services. Defenders should verify the versions of Watchfire Controller Software in use and apply the vendor-provided patches to disable the use of hard-coded cryptographic keys, which can lead to unauthorized firmware updates and control.

Read Full Story →