vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript code within the victim’s browser, potentially leading to unauthorized control. Building automation sy… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot