Thursday, October 1, 2026 Newsletter Advertise
Breaking
Cyber

BreakingCISA flags data exposure flaw in Johnson Controls EasyIO Neo

CISA says CVE-2026-64892 could let an attacker obtain sensitive information from building automation controllers used worldwide, with fixed firmware now available.

CISA flags data exposure flaw in Johnson Controls EasyIO Neo. CVE-2026-64892, Source: CISA

CISA published an industrial control systems advisory on October 1, 2026 warning of an information-exposure vulnerability in Johnson Controls EasyIO Neo Series EC and CW controllers. The advisory, tracked as ICSA-26-274-04, covers CVE-2026-64892 and republishes Johnson Controls Product Security Advisory JCI-PSA-2026-20.

What the flaw does

According to CISA, successful exploitation of the vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.

The issue is classified under CWE-200, Exposure of Sensitive Information to an Unauthorized Actor. CISA lists a CVSS v3.1 base score of 3.5 (low) with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L, and a CVSS v4.0 base score of 4.8 (medium).

CISA said no known public exploitation specifically targeting this vulnerability has been reported to the agency at this time. Gabriele Gardois reported the vulnerability to Johnson Controls, according to the advisory's acknowledgments.

Affected products

The advisory lists EasyIO Neo Series EC Controllers V3.3b63 and V3.3b62, and EasyIO Neo Series CW Controllers V3.3b25 and V3.3b24 as affected by CVE-2026-64892.

CISA describes the EC and CW as programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections.

CISA lists the deployment as worldwide, across the critical manufacturing, commercial facilities, government services and facilities, transportation systems and energy sectors. Johnson Controls is headquartered in Ireland, the advisory states.

Fixes and mitigations

Johnson Controls has released fixed versions, CISA said: the fix is available in EC firmware V3.3b64 and CW firmware V3.3b26. Users should upgrade to the fixed version or later as soon as operationally feasible and can contact their Johnson Controls representative or an authorized EasyIO distributor.

Where an immediate update is not possible, Johnson Controls recommends physical access controls to prevent unauthorized personnel from reaching device debug ports, network traffic monitoring for unusual or unauthorized access attempts, least-privilege for accounts and services interacting with the devices, firmware updates that disable debug interfaces or require authentication for debug access where possible, and intrusion detection or prevention systems.

The advisory adds that these mitigations reduce risk but may not fully remediate the vulnerability, and that users should update to the fixed versions when operationally feasible. CISA also reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

What to do

  • Upgrade affected controllers to EC firmware V3.3b64 or CW firmware V3.3b26 or later as soon as operationally feasible, contacting your Johnson Controls representative or authorized EasyIO distributor.
  • Before applying updates in production ICS/OT environments, review operational impact, back up relevant configurations, test updates in a non-production environment where feasible and follow change-management and safety procedures.
  • If you cannot update immediately, add physical access controls so unauthorized personnel cannot reach device debug ports.
  • Monitor network traffic to and from affected devices for unusual or unauthorized access attempts, and deploy intrusion detection or prevention systems to watch for exploitation attempts.
  • Apply least privilege to all accounts and services that interact with the devices, and where possible apply firmware updates that disable debug interfaces or require authentication for debug access.
  • Follow the product hardening guide or the JCI universal hardening guide on the Johnson Controls Trust Center, and see advisory JCI-PSA-2026-20 for more detailed mitigation instructions.
  • Report suspected malicious activity to CISA through established internal procedures for tracking and correlation.
Key facts and where they come from
  • Exploitation could expose sensitive information usable in further attacks.
    Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.
  • Four firmware versions across EC and CW controllers are listed as affected by CVE-2026-64892.
    Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24
  • Fixed firmware is EC V3.3b64 and CW V3.3b26.
    The fix is available in EC firmware V3.3b64 and CW firmware V3.3b26.
  • The flaw is scored CVSS v3.1 3.5 (low) and CVSS v4.0 4.8 (medium).
    3.1
    3.5
    LOW
    CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:L

    4.0
    4.8
    MEDIUM

  • CISA says no public exploitation has been reported.
    No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.
  • The weakness is CWE-200.
    Relevant CWE: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
  • The advisory republishes Johnson Controls advisory JCI-PSA-2026-20.
    Initial Republication of Johnson Controls Product Security Advisory JCI-PSA-2026-20

Read the original from CISA →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber