Incident & CVE tracker
Breaches, vulnerabilities and CVEs in physical access control, sourced from NVD, vendor advisories and primary reporting. Every vendor gets 72 hours to respond before an entry publishes; responses render on the entry.
| Incident | CVE / source | Vendor notified | Vendor response | ||||
|---|---|---|---|---|---|---|---|
| ZKTeco | ZKTeco camera config export exposes credentials without authentication | CVE-2026-8598 | HIGH | — | May 19, 2026 | None given | |
| Nice North America | Unpatched OS command injection in Nice Linear eMerge E3 controllers | CVE-2024-9441 | CRITICAL | 9.8 | April 24, 2025 | None given | |
| Johnson Controls | Software House iSTAR door controllers accepted unauthenticated ICU traffic | CVE-2024-32752 | CRITICAL | 9.1 | June 6, 2024 | None given |