Trane manufactures building automation and HVAC control systems including the Tracer SC platform and ComfortLink II ecosystem, which are deployed across commercial and residential infrastructure where they manage critical climate and facility operations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through code-injection weaknesses, hard-coded credentials, and input-handling flaws characteristic of web-facing control interfaces and embedded firmware. Defenders should prioritize inventory and network segmentation of these systems, particularly internet-connected instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trane over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28252CRITICAL A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root | Mar 12, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-28256CRITICAL A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and ta | Mar 12, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-28255CRITICAL A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts. | Mar 12, 2026 | 9.8 | 29 | NO | NO |
CVE-2021-38450HIGH The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. | Oct 27, 2021 | 8.8 | 28 | NO | NO |
CVE-2015-2868CRITICAL An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the T | Jan 6, 2017 | 9.8 | 28 | NO | NO |
CVE-2015-2867CRITICAL A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system. | Jan 6, 2017 | 9.8 | 26 | NO | NO |
CVE-2021-38448HIGH The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. | Nov 22, 2021 | 7.6 | 25 | NO | NO |
CVE-2026-28254HIGH A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotect | Mar 12, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-28253HIGH A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-servic | Mar 12, 2026 | 7.5 | 24 | NO | NO |
CVE-2016-4526HIGH ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory. | Sep 19, 2016 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trane.
Media articles that mention a CVE ID that affects a product developed by Trane — matched by CVE ID, not by vendor name.