Upgrade to EasyIO Neo Series EC Controllers V3.3b64 or later and CW Controllers V3.3b26 or later. If immediate update is not possible, enforce HTTPS/TLS for all web-based management access, disable HTTP access entirely, place devices on isolated and segmented networks behind a firewall, use a VPN for remote access, and monitor network traffic for unencrypted sensitive data. Apply the recommendations in the Johnson Controls Hardening Guide and refer to advisory JCI-PSA-2026-30 for further guidance.
Quick answers
What is CVE-2026-64893?
Upgrade to EasyIO Neo Series EC Controllers V3.3b64 or later and CW Controllers V3.3b26 or later. If immediate update is not possible, enforce HTTPS/TLS for all web-based management access, disable HTTP access entirely, place devices on isolated and segmented networks behind a firewall, use a VPN for remote access, and monitor network traffic for unencrypted sensitive data. Apply the recommendations in the Johnson Controls Hardening Guide and refer to advisory JCI-PSA-2026-30 for further guidance.
How severe is CVE-2026-64893?
medium, CVSS 5.4
Is CVE-2026-64893 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-64893 be mitigated?
Upgrade to EasyIO Neo Series EC Controllers V3.3b64 or later and CW Controllers V3.3b26 or later. If immediate update is not possible, enforce HTTPS/TLS for all web-based management access, disable HTTP access entirely, place devices on isolated and segmented networks behind a firewall, use a VPN for remote access, and monitor network traffic for unencrypted sensitive data. Apply the recommendations in the Johnson Controls Hardening Guide and refer to advisory JCI-PSA-2026-30 for further guidance.
CVSS
5.4
Vendor
Johnson Controls
Published
Oct 2, 2026 · 03:06
Patch
Unknown / not confirmed
Affected products
EasyIO Neo Series EC Controllers, EasyIO Neo Series CW Controllers
Mitigation
Upgrade to EasyIO Neo Series EC Controllers V3.3b64 or later and CW Controllers V3.3b26 or later. If immediate update is not possible, enforce HTTPS/TLS for all web-based management access, disable HTTP access entirely, place devices on isolated and segmented networks behind a firewall, use a VPN for remote access, and monitor network traffic for unencrypted sensitive data. Apply the recommendations in the Johnson Controls Hardening Guide and refer to advisory JCI-PSA-2026-30 for further guidance.
Johnson Controls has identified a vulnerability in EasyIO Neo Series EC and CW Controllers that allows cleartext transmission of sensitive information over the network. Exploitation could enable interception of credentials and session data. Fixed firmware versions are now available.