Apply v4.1.0 or later patches for all Airwalls. Additional mitigations: store cryptographic keys in a secure KMS/HSM, implement key rotation, use unique keys per device, remove hardcoded keys from source code, apply least privilege, use static analysis and secrets scanning, encrypt keys at rest and in transit, audit key access, and follow the JCI hardening guide.
Quick answers
What is CVE-2026-34492?
Apply v4.1.0 or later patches for all Airwalls. Additional mitigations: store cryptographic keys in a secure KMS/HSM, implement key rotation, use unique keys per device, remove hardcoded keys from source code, apply least privilege, use static analysis and secrets scanning, encrypt keys at rest and in transit, audit key access, and follow the JCI hardening guide.
How severe is CVE-2026-34492?
high, CVSS 7
Is CVE-2026-34492 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-34492 be mitigated?
Apply v4.1.0 or later patches for all Airwalls. Additional mitigations: store cryptographic keys in a secure KMS/HSM, implement key rotation, use unique keys per device, remove hardcoded keys from source code, apply least privilege, use static analysis and secrets scanning, encrypt keys at rest and in transit, audit key access, and follow the JCI hardening guide.
CVSS
7
Vendor
Johnson Controls Inc.
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Johnson Controls Inc. Airwall
Mitigation
Apply v4.1.0 or later patches for all Airwalls. Additional mitigations: store cryptographic keys in a secure KMS/HSM, implement key rotation, use unique keys per device, remove hardcoded keys from source code, apply least privilege, use static analysis and secrets scanning, encrypt keys at rest and in transit, audit key access, and follow the JCI hardening guide.
Two vulnerabilities in Johnson Controls Airwall could allow attackers to decrypt sensitive data, bypass authentication, and read arbitrary files. The flaws affect Airwall versions up to 4.0.4 and are rated medium/high severity. Johnson Controls has released patches in v4.1.0 and recommends immediate application.