Skip to content
ThreatCluster

Vulnerability in Johnson Controls EasyIO Neo Series Exposes Sensitive Data

First seen 2 Oct 2026, 00:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 01:05 UTC
  • •CVE-2026-64893 allows interception of sensitive data in EasyIO Neo controllers.
  • •Affected versions include EC Controllers V3.3b62, V3.3b63 and CW Controllers V3.3b24, V3.3b25.
  • •Users are urged to upgrade to fixed firmware or implement mitigations immediately.

Johnson Controls disclosed a vulnerability (CVE-2026-64893) affecting the EasyIO Neo Series EC and CW Controllers, which could allow attackers to intercept sensitive information transmitted in cleartext. The affected versions include EC Controllers V3.3b62, V3.3b63, and CW Controllers V3.3b24, V3.3b25. This vulnerability poses a high risk due to the potential for credential and session data theft. The company has released fixed firmware versions (V3.3b64 for EC and V3.3b26 for CW) and recommends users upgrade as soon as feasible. Until then, users are advised to implement mitigations such as enforcing HTTPS/TLS and isolating devices on a segmented network. The vulnerability affects critical infrastructure sectors including manufacturing, transportation, and energy, and is deployed worldwide.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Vulnerability disclosed
Johnson Controls published details on CVE-2026-64893 affecting EasyIO Neo Controllers, allowing data interception.
Cisa
2026-10-01
Patch released
Fixed versions V3.3b64 for EC and V3.3b26 for CW Controllers were made available to users.
Cisa
2026-10-01
CVE-2026-64892 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-64893 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track Johnson Controls, Inc and CVE-2026-64892 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of EasyIO Neo are affected?
The affected versions include EC Controllers V3.3b62, V3.3b63 and CW Controllers V3.3b24, V3.3b25.
What should I do if I cannot patch immediately?
Implement mitigations such as enforcing HTTPS/TLS and isolating devices on a segmented network.
Is there a fix available for this vulnerability?
Yes, Johnson Controls has released fixed firmware versions V3.3b64 for EC and V3.3b26 for CW Controllers.