A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-78319, has been disclosed in building automation controllers from the manufacturer SAUTER. The flaw carries a CVSS score of 9.8, indicating its extreme severity. An unauthenticated remote attacker could exploit this vulnerability to achieve full control over affected devices, which are responsible for managing critical building systems like heating, ventilation, and air conditioning (HVAC). A successful attack could lead to physical disruption, equipment damage, and unsafe environmental conditions. SAUTER has released firmware updates to address the issue, and asset owners are urged to patch immediately.
The vulnerability is a Time-of-Check to Time-of-Use (TOCTOU) race condition, cataloged as CWE-367. It exists in the firmware update mechanism of the affected controllers. An attacker can exploit this by sending a legitimate firmware update request and then, in the small window of time between the device checking the file and actually using it, replacing the legitimate file with a malicious one. This tricks the device into accepting and executing the attacker's arbitrary code, leading to a full compromise of the controller.
The flaw was discovered by researchers during the Cyberdefence Campus Domotics Hackathon 2026 and was disclosed responsibly via CERT@VDE.
The vulnerability impacts the following SAUTER products and firmware versions:
Specific affected hardware models include:
ecos504ecos505modu612-LCmodu660-ASmodu680-ASAs of the public disclosure on September 1, 2026, there have been no reports of a public proof-of-concept (PoC) exploit or any signs of active in-the-wild exploitation. However, given the critical nature of the flaw and its direct impact on physical systems, the likelihood of future exploitation is high.
Exploitation of CVE-2026-78319 could have severe real-world consequences. An attacker with control over a building automation controller could:
The following patterns may help identify vulnerable or compromised systems:
Apply the firmware updates provided by SAUTER to remediate the TOCTOU vulnerability.
Isolate building automation systems on a separate network segment, away from corporate IT and the internet, to limit exposure.
Enable security features like firmware downgrade protection after applying the patch.
CERT@VDE publicly discloses the details of CVE-2026-78319.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.