Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Building Control Systems

A serious security weakness has been found in certain building management and control systems that could allow hackers to take control remotely or disrupt services. This matters because these systems often manage heating, ventilation, and other essential functions in small businesses and organisations.

02 September 2026

Reference: CVE-2021-31886

1. What is being reported?

Researchers have identified a vulnerability in several versions of APOGEE and TALON building control products. The problem is with their FTP server, which does not properly check the size of a login command. This flaw can let attackers cause the system to crash or run harmful code remotely.

2. What this means in plain English

If your organisation uses these building control systems, an attacker could potentially disrupt your heating or ventilation, or worse, take control of the system. This could lead to downtime or safety issues. The risk is higher if these systems are connected to the internet or poorly secured networks.

3. Could this affect a small business?

Small businesses or charities using APOGEE or TALON building management systems with affected versions could be vulnerable. If you do not use these specific systems, or your systems are not connected externally, you are less likely to be affected.

4. What to do now

  • Check if your building control systems are from APOGEE or TALON and identify their versions.
  • Contact your system supplier or IT provider to confirm if your versions are affected and ask about available updates or patches.
  • Ensure these control systems are not directly accessible from the internet and are protected behind secure networks.
  • Monitor your systems for unusual activity and have a plan to respond if you suspect a security incident.

5. Ask your IT provider

Can you confirm if our building control systems are affected by the CVE-2021-31886 vulnerability and advise on steps to secure or update them?

6. Bottom line

If you use APOGEE or TALON building control systems, act now to check and secure them against a critical vulnerability.

Information based on NVD, CISA KEV, and reputable security reporting.

Back to Vulnerability Briefs