CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
CVE-2026-64892 affects EC and CW controller firmware; attacker could access privileged data
Key Takeaways
- CISA has issued an ICS advisory (ICSA-26-274-04) for CVE-2026-64892 affecting Johnson Controls EasyIO Neo Series controllers.
- Four firmware versions are vulnerable: EC V3.3b63, EC V3.3b62, CW V3.3b25, and CW V3.3b24.
- The vulnerability could allow an attacker to access sensitive information, potentially facilitating further attacks.
- Johnson Controls has released fixed firmware: EC V3.3b64 and CW V3.3b26.
- No public exploitation has been confirmed, but defensive mitigations are recommended until patching is completed.
Related Security News
Critical Vulnerabilities Discovered in Armatura LLC Armatura One Platform
Armatura LLC's Armatura One and Armatura One (USA) platforms are affected by five vulnerabilities spanning critical and high severity. The most severe, CVE-2023-46604, is a deserialization flaw in embedded Apache ActiveMQ that allows unauthenticated remote code execution with highest privilege. Additional issues involve hard-coded cryptographic keys, fixed database passwords, and sensitive data leakage into logs. Versions prior to 4.7.2 (global) and 4.6.1_USA are affected. Patches have been released.
