Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms

Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms

Posted on January 26, 2026January 26, 2026 By CWS

Vulnerabilities found by researchers in Dormakaba bodily entry management programs might have allowed hackers to remotely open doorways at main organizations.

The safety holes had been found by consultants at SEC Seek the advice of, a cybersecurity consulting agency beneath Atos-owned Eviden, in Dormakaba’s Exos central administration software program, a {hardware} entry supervisor, and registration items that allow entry by way of a keypad, fingerprint reader, or chip card.

A number of varieties of vulnerabilities had been recognized, together with hardcoded credentials and encryption keys, weak passwords, lack of authentication, insecure password technology, native privilege escalation, knowledge publicity, path traversal, and command injection points.

The susceptible product is principally utilized by massive enterprises in Europe, together with industrial corporations, vitality suppliers, logistics companies, and airport operators. 

Exploitation of the issues recognized by SEC Seek the advice of researchers might have allowed menace actors to straight unlock doorways, acquire entry PINs, or conduct additional assaults within the compromised atmosphere. 

“Just a few thousand clients had been probably affected, with a small subset having high-security necessities,” Dormakaba instructed SecurityWeek. Commercial. Scroll to proceed studying.

In whole, greater than 20 vulnerabilities had been found and reported to the seller, which over the previous yr and a half has been working to launch patches and hardening pointers. 

Dormakaba has additionally been working with main clients to make sure that their entry programs are not susceptible. 

In line with the seller, “To use the vulnerabilities, an attacker wants prior entry to the customer-specific infrastructure (community or {hardware}). Consequently, exploitation would solely be doable from inside the buyer’s personal protected community.”

Nevertheless, SEC Seek the advice of has recognized just a few dozen internet-exposed programs that had been susceptible and will have been focused by hackers to open doorways straight from the net. 

Dormakaba said that it’s “not conscious of any circumstances the place the recognized vulnerabilities have been exploited.”

The cybersecurity agency has revealed a video displaying how an attacker might have exploited the vulnerabilities to open doorways utilizing specifically crafted requests:

Associated: Cost System Vendor Took Yr+ to Patch Infinite Card High-Up Hack: Safety Agency

Associated: Researcher Says Healthcare Facility’s Doorways Hackable for Over a Yr

Associated: Organizations Sluggish to Defend Doorways In opposition to Hackers: Researcher

Security Week News Tags:Access, Doors, Enabled, European, Firms, Flaws, Hackers, Major, System, Unlock

Post navigation

Previous Post: Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
Next Post: Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware

Related Posts

FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes Security Week News
North Korean Hackers Target macOS Developers via Malicious VS Code Projects North Korean Hackers Target macOS Developers via Malicious VS Code Projects Security Week News
Lema AI Secures M to Revolutionize Third-Party Risk Lema AI Secures $24M to Revolutionize Third-Party Risk Security Week News
‘MadeYouReset’ HTTP2 Vulnerability Enables Massive DDoS Attacks ‘MadeYouReset’ HTTP2 Vulnerability Enables Massive DDoS Attacks Security Week News
In Other News: PQC Adoption, New Android Spyware, FEMA Data Breach In Other News: PQC Adoption, New Android Spyware, FEMA Data Breach Security Week News
Helmet Security Emerges From Stealth Mode With  Million in Funding Helmet Security Emerges From Stealth Mode With $9 Million in Funding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations
  • North Korean Hackers Exploit AI for Enhanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations
  • North Korean Hackers Exploit AI for Enhanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News