Trane Tracer SC, Tracer SC+, and Tracer Concierge
Trane Tracer SC, Tracer SC+, and Tracer Concierge products contain five critical vulnerabilities including broken cryptographic algorithms, memory allocation flaws, missing authorization, and hardcoded credentials that could allow attackers to bypass authentication, execute arbitrary commands, or cause denial-of-service. Affected versions are Tracer SC <v4.4_SP7, Tracer SC+ <v6.3.2310, and Tracer Concierge <v6.3.2310, with patches available in Tracer SC+ v6.30.2313.
Summary
Trane Tracer SC, Tracer SC+, and Tracer Concierge products contain five critical vulnerabilities including broken cryptographic algorithms, memory allocation flaws, missing authorization, and hardcoded credentials that could allow attackers to bypass authentication, execute arbitrary commands, or cause denial-of-service. Affected versions are Tracer SC <v4.4_SP7, Tracer SC+ <v6.3.2310, and Tracer Concierge <v6.3.2310, with patches available in Tracer SC+ v6.30.2313.
Indicators of Compromise
- cve — CVE-2026-28252
- cve — CVE-2026-28253
- cve — CVE-2026-28254
- cve — CVE-2026-28255
- cve — CVE-2026-28256