Johnson Controls Disclosed Controller Vulnerability
A security flaw in EasyIO Neo controllers could allow unauthorized access to sensitive system information.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust that industrial control systems in your area are adequately protected from cyber attacks?
Johnson Controls has issued an advisory regarding a newly identified vulnerability, tracked as CVE-2026-64892, affecting several EasyIO Neo Series controller models. The flaw potentially exposes sensitive information to unauthorized users, though no public exploitation has been reported.
Why it matters
Security advisories are critical for maintaining the integrity of building automation systems that rely on these controllers. Prompt identification and mitigation help prevent attackers from potentially compromising sensitive operational data within managed environments.
The vulnerability, identified as CVE-2026-64892, impacts EasyIO Neo Series EC Controllers (versions V3.3b63 and V3.3b62) and CW Controllers (versions V3.3b25 and V3.3b24).
The players
Johnson Controls
This Ireland-based multinational conglomerate specializes in the manufacturing of fire, HVAC, and security equipment for buildings.
Gabriele Gardois
He is the security researcher responsible for identifying and reporting the flaw to the manufacturer.
The details
Attackers can leverage this vulnerability to gain unauthorized access to sensitive system information stored within the affected hardware. The issue was brought to the attention of the Ireland-based manufacturer by researcher Gabriele Gardois.
Timeline
The vulnerability advisory was released on October 1, 2026.
The Tech Race
This disclosure highlights the critical security maintenance required for the EasyIO Neo Series controller infrastructure as it faces evolving digital threats. It underscores the broader industry challenge of securing legacy and widely deployed industrial hardware against modern remote exploitation.
Users of these controller series should verify their current firmware versions against the advisory to assess their risk levels. Organizations must monitor official channels for upcoming patches or hardening guidance to secure their building management systems.
The takeaway
Maintaining updated firmware is a primary defense against unauthorized access in building control networks. System administrators should prioritize auditing hardware versions to ensure they are not operating on deprecated, vulnerable software.
Further reading
For broader insights on digital safety, visit our Cybersecurity section.
More information
Review the latest Johnson Controls cybersecurity hardening guidelines for official mitigation steps.
Source note: This article includes information reported by Cisa.
Live Poll
Do you trust that industrial control systems in your area are adequately protected from cyber attacks?







