Claroty finds 23 vulnerabilities in Copeland XWEB Pro and additional RCE flaws in Danfoss AK-SM 800A refrigeration controllers

Researchers found serious security flaws in two widely used commercial refrigeration control systems that could let attackers remotely tamper with cooling equipment. Claroty Team82 reported 23 vulnerabilities in Copeland XWEB Pro controllers, including bugs that can be chained to bypass protections and gain root-level remote code execution, plus multiple remote-code-execution flaws in Danfoss AK-SM 800A controllers. Both vendors have issued patches.
Why it matters: Organizations that rely on connected refrigeration, such as food, cold-chain, and industrial operators, could face spoiled inventory or operational disruption if these systems are exposed and unpatched. Owners should identify affected controllers and apply vendor fixes promptly.

Sources

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
SecurityWeek News 2026.08.14 100% relevant
The article establishes a concrete new vulnerability disclosure affecting named ICS/OT refrigeration products, with patch availability and clear real-world impact.
← Back to all stories