ICSA-26-211-09
·
Published 2026-07-30
·
View on CISA ICS-CERT ↗
Watchfire Controller Software
CVSS 5.7
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.
CVEs (1)
Remediations
- Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.
- Watchfire has issued patches to disable the use of the existing certificate as follows: BC550 12.30: Patch to 12.31 SP1BC750 11.33: Patch to 11.34BC750 12.35: Patch to 12.36 SP1BC760 12.38: Patch to 12.41 SP1BC760 13.00: Patch to 14.00 SP1BC760DC 12.39: Patch to 12.41 SP1
Affected Vendors
Watchfire
Affected Products (4)
Watchfire
·
BC550
12.30
Watchfire
·
BC750
11.33|12.35
Watchfire
·
BC760
12.38|13.00
Watchfire
·
BC760DC
12.39
Affected Sectors
Commercial Facilities, Critical Manufacturing, Healthcare and Public Health, Financial Services
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more