Security Flaws Found in EasyIO FG Firmware

Researchers identified two vulnerabilities in Johnson Controls firmware that could permit unauthorized device access.

Updated on Oct. 6, 2026 in Cybersecurity

Isometric editorial illustration of a blocky industrial hardware controller with detailed copper-colored circuitry, representing cybersecurity risks in automation equipment.
Johnson Controls has warned of security vulnerabilities in EasyIO FG firmware, with CISA urging facility operators to isolate affected devices from business networks. AI Illustration. Upload story photo >

Live Poll

Do you trust that manufacturers are adequately securing critical infrastructure devices in your area?

Johnson Controls has identified security vulnerabilities within its EasyIO FG firmware, prompting a formal warning from CISA. The flaws, designated CVE-2026-27872 and CVE-2026-27873, impact firmware versions 2.0b52 and earlier.

Why it matters

While no public exploitation has been reported, these vulnerabilities could allow attackers to gain unauthorized access to hardware. CISA advises operators to isolate affected devices from business networks to mitigate potential risks.

The vulnerabilities affect EasyIO FG firmware version 2.0b52 and earlier. These two identified CVEs require high attack complexity and are not exploitable remotely.

The players

Johnson Controls

An Irish-domiciled industrial conglomerate that manufactures the affected EasyIO FG hardware products.

CISA

The Cybersecurity and Infrastructure Security Agency is the U.S. federal agency responsible for issuing national warnings regarding critical infrastructure vulnerabilities.

University of Calgary

A public research university located in Canada whose researchers identified the specific firmware flaws.

The details

Researchers from the University of Calgary discovered the security gaps, which involve technical flaws that could bypass device authentication. CISA recommends that all affected equipment be placed behind firewalls and that any necessary remote access be strictly limited to secure methods like Virtual Private Networks.

Timeline

  1. CISA released the formal security advisory on October 6, 2026.

The Tech Race

This incident follows the defensive framework established in the CISA control systems security practices to secure industrial hardware. The discovery highlights the ongoing challenge of maintaining security across legacy firmware versions in an increasingly interconnected industrial landscape.

Users operating these devices must immediately move hardware behind firewalls to prevent unauthorized access. Administrators should mandate the use of Virtual Private Networks for any required remote management to secure their infrastructure.

The takeaway

Proactive isolation of industrial devices remains the most effective defense against unpatched firmware vulnerabilities. Operators should prioritize network segmentation to ensure that even discovered flaws cannot be leveraged by malicious actors.

Further reading

For broader context on protecting digital infrastructure, visit the /tech/cybersecurity/ section.

More information

Review the full list of CISA control systems security practices for further guidance on device isolation.

Source note: This article includes information reported by Cisa.

Live Poll

Do you trust that manufacturers are adequately securing critical infrastructure devices in your area?