These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-27844 is an Uncaught Exception vulnerability in the Controller 6000 and Controller 7000 diagnostic web interface. An authenticated and authorized operator can trigger a Controller restart by sending specific requests, resulting in a temporary denial of service. The vulnerability, classified as CWE-248 Uncaught Exception, allows an authenticated and authorized operator to trigger a Controller rest [truncated]
CVE-2026-27790 is an Uncaught Exception vulnerability in T20 Readers. An authenticated and authorized operator can trigger a restart by sending specific requests, resulting in a temporary denial of service. Affected versions include Command Centre 9.50 prior to vCR9.50.260616a, 9.40 prior to vCR9.40.260616a, 9.30 prior to vCR9.30.260616a, 9.20 prior to vCR9.20.260616a, and all versions of 9.10 and prior. [truncated]
An Incorrect Privilege Assignment vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. This could lead to unauthorized actions within the Command Centre Server environment. The vulnerability has been assigned a CVSS score of 5.3, indicating a medium severity level. Affected vers [truncated]
CVE-2026-25193 is a HIGH severity vulnerability (CVSS 8.1) involving insertion of sensitive information into log files (CWE-532) in Gallagher Command Centre Service installers. The issue was published on 2026-05-25 and last modified on 2026-05-26. When administrators install Command Centre Services using a custom Service Account rather than the default Network Service account, the installer may write Serv [truncated]
Cleartext Transmission of Sensitive Information (CWE-319) vulnerability in Gallagher Hanwha VMS and NxWitness VMS integrations. Unprivileged users with local network access can view live video streams. Affected versions are prior to 9.10.017 for NxWitness VMS and prior to 9.10.025 for Hanwha VMS. This vulnerability allows unauthorized access to sensitive video feeds, potentially leading to privacy breache [truncated]
The Gallagher Command Centre Server is vulnerable to an Improper Locking issue (CWE-667) in the Morpho integration, which allows a privileged operator to cause a limited denial-of-service condition. This issue affects multiple versions of the Command Centre Server, including 9.40, 9.30, 9.20, 9.10, and all versions of 9.00 and prior. Operators and administrators should assess their exposure, apply patches [truncated]