← Back to Feed

Johnson Controls Inc. TL280

CVE-2026-27871

August 6, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63  CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27871 Hardcoded credentials refer to usernames, passwords, or other authentication information that are embedded directly into the source code of a firmware file. These credentials are often used to access system login and other areas of an application. View CVE Details Affected Products Johnson Controls Inc. TL280 Vendor:Johnson Controls Inc. Product Version:Johnson Controls Inc. TL280: <5.63 Product Status:known_affected Remediations Vendor fixTo help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63. MitigationJohnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments. MitigationMonitor device access logs for any anomalous authentication activity. MitigationRotate any shared or downstream credentials that may have been derived from or associated with the hard-coded values. MitigationImplement network segmentation and place ICS/SCADA devices and systems behind firewalls, isolating them from the business network.

Key Takeaways

  • CISA released advisory ICSA-26-218-02 regarding CVE-2026-27871 affecting Johnson Controls TL280 building management controllers.
  • The vulnerability could allow unauthorized access to building management systems, potentially impacting physical security and environmental controls.
  • Johnson Controls has published security guidance through their trust center — organizations should update affected firmware and restrict network access.
  • Building management system operators should isolate TL280 controllers from internet exposure and apply vendor-recommended mitigations.
☕ Buy a Coffee