02 September 2026
Reference: CVE-2021-31886
1. What is being reported?
Researchers have identified a vulnerability in several versions of APOGEE and TALON building control products. The problem is with their FTP server, which does not properly check the size of a login command. This flaw can let attackers cause the system to crash or run harmful code remotely.
2. What this means in plain English
If your organisation uses these building control systems, an attacker could potentially disrupt your heating or ventilation, or worse, take control of the system. This could lead to downtime or safety issues. The risk is higher if these systems are connected to the internet or poorly secured networks.
3. Could this affect a small business?
Small businesses or charities using APOGEE or TALON building management systems with affected versions could be vulnerable. If you do not use these specific systems, or your systems are not connected externally, you are less likely to be affected.
4. What to do now
- Check if your building control systems are from APOGEE or TALON and identify their versions.
- Contact your system supplier or IT provider to confirm if your versions are affected and ask about available updates or patches.
- Ensure these control systems are not directly accessible from the internet and are protected behind secure networks.
- Monitor your systems for unusual activity and have a plan to respond if you suspect a security incident.
5. Ask your IT provider
Can you confirm if our building control systems are affected by the CVE-2021-31886 vulnerability and advise on steps to secure or update them?
6. Bottom line
If you use APOGEE or TALON building control systems, act now to check and secure them against a critical vulnerability.
Information based on NVD, CISA KEV, and reputable security reporting.