
Five chained vulnerabilities in Trane Tracer SC+ HVAC controllers give remote attackers root access to data center cooling systems. A broken substitution cipher, hardcoded global credentials, and unauthenticated API endpoints combine into a full compromise chain. Firmware v6.30.2313 patches all five flaws.

Two critical vulnerabilities in EnOcean SmartServer IoT (CVE-2026-20761, CVE-2026-22885) allow remote, unauthenticated attackers to gain root access to building management system controllers via crafted IP-852 UDP packets. Analysis, MITRE ATT&CK mapping, and defensive recommendations.