โ† Back to Feed

Johnson Controls EasyIO Neo Series EC and CW Controllers

CVE-2026-64893

October 1, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL

Johnson Controls EasyIO Neo Series controllers have a vulnerability (CVE-2026-64893) that transmits sensitive information in cleartext, allowing interception of credentials and session data. The flaw affects EC and CW controllers used in building automation. Fixed versions are available. ๐Ÿ“Œ **Analyst Note:** Cleartext transmission in building automation controllers is a serious security gap; organizations should prioritize upgrading and ensure network segmentation to prevent lateral movement from compromised controllers.

Key Takeaways

  • CVE-2026-64893 in Johnson Controls EasyIO Neo Series EC and CW Controllers allows attackers to intercept cleartext transmission of sensitive information including credentials and session data.
  • These building automation edge controllers manage HVAC, lighting, and energy systems in commercial buildings, making exploitation potentially impactful on critical infrastructure sectors.
  • Johnson Controls has released fixed versions for the affected controllers, and users are advised to upgrade immediately to prevent credential and session data interception.
โ˜• Buy a Coffee