- What is CVE-2026-64892?
- Upgrade to Johnson Controls EC firmware V3.3b64 or later and CW firmware V3.3b26 or as soon as operationally feasible after testing in non-production environments. Apply physical access controls to prevent unauthorized access to device debug ports. Monitor network traffic for unusual or unauthorized access attempts. Apply least privilege principles to all accounts and services interacting with affected devices. Where possible, apply firmware updates that disable debug interfaces or require authentication for debug access. Deploy intrusion detection/prevention systems. Follow the Johnson Controls product hardening guide and universal hardening guide.
- How severe is CVE-2026-64892?
- medium, CVSS 4.8
- Is CVE-2026-64892 known to be exploited?
- It is not marked known-exploited in this record.
- How should CVE-2026-64892 be mitigated?
- Upgrade to Johnson Controls EC firmware V3.3b64 or later and CW firmware V3.3b26 or as soon as operationally feasible after testing in non-production environments. Apply physical access controls to prevent unauthorized access to device debug ports. Monitor network traffic for unusual or unauthorized access attempts. Apply least privilege principles to all accounts and services interacting with affected devices. Where possible, apply firmware updates that disable debug interfaces or require authentication for debug access. Deploy intrusion detection/prevention systems. Follow the Johnson Controls product hardening guide and universal hardening guide.