Low severity3.7NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026
CVE-2026-22885
CVE-2026-22885
Description
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- enoceanwiki.atlassian.net/wiki/spaces/DrftSSIoT/pages/1475410/SmartServer+IoT+Release+Notesnvd
- enoceanwiki.atlassian.net/wiki/spaces/IEC/pages/288063529/Enhancing+Securitynvd
- github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-050-01.jsonnvd
- www.cisa.gov/news-events/ics-advisories/icsa-26-050-01nvd
News mentions
1- ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News · May 4, 2026