Vulnerability intelligence
CVE-2026-22885
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.
CVSS Score
3.7
Low
EPSS — Exploit Probability
0.4%
Riskier than 29% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Apr 30, 2026 · latest Apr 30, 2026
Coverage timeline
-
Remote flaws in EnOcean SmartServer expose buildings to hackingwww.securityweek.com · Apr 30, 2026