← Back to Feed

Johnson Controls Inc. Airwall

CVE-2026-64887CVE-2026-34492

August 13, 2026 · CISA (US-CERT) · Severity: CRITICAL

Johnson Controls Airwall versions up to 4.0.4 are impacted by a hardcoded cryptographic key (CVE-2026-64887) and an external file control vulnerability (CVE-2026-34492). Exploitation can lead to decryption of sensitive data, authentication bypass, and unauthorized file access. Johnson Controls recommends defensive mitigations until patches are available.

Key Takeaways

  • CVE-2026-64887 reveals a hardcoded cryptographic key in Johnson Controls Airwall versions 4.0.4 and below. This hardcoded key allows attackers to decrypt sensitive data and bypass authentication controls. CVE-2026-34492 enables external control of file paths for unauthorized access.
☕ Buy a Coffee