Vulnerability in Johnson Controls EasyIO Neo Series Exposes Sensitive Data
Article Content
- •CVE-2026-64893 allows interception of sensitive data in EasyIO Neo controllers.
- •Affected versions include EC Controllers V3.3b62, V3.3b63 and CW Controllers V3.3b24, V3.3b25.
- •Users are urged to upgrade to fixed firmware or implement mitigations immediately.
Johnson Controls disclosed a vulnerability (CVE-2026-64893) affecting the EasyIO Neo Series EC and CW Controllers, which could allow attackers to intercept sensitive information transmitted in cleartext. The affected versions include EC Controllers V3.3b62, V3.3b63, and CW Controllers V3.3b24, V3.3b25. This vulnerability poses a high risk due to the potential for credential and session data theft. The company has released fixed firmware versions (V3.3b64 for EC and V3.3b26 for CW) and recommends users upgrade as soon as feasible. Until then, users are advised to implement mitigations such as enforcing HTTPS/TLS and isolating devices on a segmented network. The vulnerability affects critical infrastructure sectors including manufacturing, transportation, and energy, and is deployed worldwide.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Johnson Controls, Inc and CVE-2026-64892 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of EasyIO Neo are affected?
What should I do if I cannot patch immediately?
Is there a fix available for this vulnerability?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…