← Back to Feed
Watchfire Controller Software
CVE-2026-5846
July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL
This advisory from CISA describes a vulnerability in Watchfire Controller Software, identified as CVE-2026-5846. The issue stems from hard-coded RSA private keys and X.509 certificates used for HTTPS/TLS, which could enable an attacker to gain full control of the controller. Watchfire has released patches, and users are advised to upgrade their software to the recommended versions.
Key Takeaways
- CVE-2026-5846 involves hard-coded cryptographic keys in Watchfire Controller Software.
- Exploitation could allow an attacker to gain full control of the affected controller.
- Watchfire has issued patches; users should upgrade to the specified fixed versions.