Our takeCISA warns that Watchfire BC550/750/760 controllers before listed fixed versions let attackers push malicious firmware and take full control. If you run these, update now.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update Watchfire BC550 (to >12.30), BC750 (>11.33/12.35), BC760 (>12.38/13.00) and BC760DC (>12.39) immediately. Successful exploitation lets an attacker push malicious firmware and take full control of the controller.
What this means for you — Lean IT orgs:If you operate any Watchfire BC550, BC750, BC760 or BC760DC sign controllers, update the software to the latest version right away. Most smaller teams without these digital signs can ignore this.
What this means for you — MSP:Check every client running Watchfire BC550, BC750, BC760 or BC760DC controllers and ensure they are updated beyond the listed vulnerable versions. This is a high-impact firmware update vulnerability that grants full controller takeover.
What this means for you — Researcher:CISA ICSA-26-211-09 details a firmware-update vulnerability (CVE-2026-5846) in Watchfire BC550 12.30, BC750 11.33/12.35, BC760 12.38/13.00 and BC760DC 12.39 that lets an attacker deliver malicious firmware and gain full control.