CVE-2026-5846: Watchfire BC550
Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
Affected products
- Watchfire BC550: version 12.30 only
- Watchfire BC750: version 11.33 only; version 12.35 only
- Watchfire BC760: version 12.38 only; version 13.00 only
- Watchfire BC760DC: version 12.39 only
Published 2026-07-30. Last modified 2026-09-08.