
Two critical vulnerabilities in EnOcean SmartServer IoT (CVE-2026-20761, CVE-2026-22885) allow remote, unauthenticated attackers to gain root access to building management system controllers via crafted IP-852 UDP packets. Analysis, MITRE ATT&CK mapping, and defensive recommendations.

Three CODESYS vulnerabilities (CVE-2025-41658/59/60) let attackers backdoor Soft PLCs from hundreds of manufacturers. Full attack chain analysis and defensive playbook for OT security teams.