- CISA reports a sensitive-data exposure flaw, CVE-2026-64892, in Johnson Controls EasyIO Neo EC and CW controllers. Fixed firmware is available, and no public exploitation has been reported to CISA.
- The advisory asks users to test updates and follow change and safety procedures first, so the patch is a planned project in a live building.
- Find out whether you run affected firmware, who can reach the debug ports, and who owns the update schedule.
A building cannot restart like a web server
Web teams can often patch and restart a server quickly. A building controller is harder. It helps run heating, lighting and energy use in a workplace that people are using. The lesson here is that in operational technology, the patch is the short part of the job. The long part is choosing when a running building can take it.
Owners of Johnson Controls EasyIO Neo EC and CW controllers now face that choice. CISA, the US cyber agency, published an advisory on October 1, 2026.
What CISA reported
The flaw is tracked as CVE-2026-64892. CISA says a successful attacker could gain access to sensitive information. That information could then be used to conduct further attacks against the system.
The weakness type is CWE-200. In plain terms, information reaches a person who should not see it.
Four firmware versions are affected. On EC controllers, they are V3.3b62 and V3.3b63. On CW controllers, they are V3.3b24 and V3.3b25.
Johnson Controls has released repaired firmware. EC units should move to V3.3b64 or later. CW units should move to V3.3b26 or later.
Gabriele Gardois reported the flaw to Johnson Controls. CISA says it has no report of public exploitation aimed at this flaw so far.
What these controllers do
CISA describes the EC and CW as programmable edge controllers for building automation. They run building functions such as heating and cooling, lighting and energy use. They link to other equipment through BACnet and Modbus. These are shared protocols that let gear from different makers work together.
CISA files the devices under five infrastructure sectors. They are critical manufacturing, commercial facilities, government, transportation and energy. The advisory does not say how many devices are in use.
What the advisory leaves out
The advisory does not explain how the exposure works. It also gives no severity score in its text. That limits what a leader can conclude about the flaw.
The interim steps offer a hint. They tell users to keep unauthorised people away from device debug ports. They also suggest firmware that turns off debug interfaces or demands a login first. Debug access may therefore matter to the risk. The advisory does not say the flaw sits there, so this is an inference.
One more point stands out. A data leak is often a first step, not the final damage. CISA's own wording points that way, since it says the data could support further attacks.
Why the fix is a project, not a click
CISA and Johnson Controls say to upgrade once operations allow. Before that, check what the change will do to the running site. Save the current settings. Try the update on a test system if you can. Follow your own change and safety rules.
That is the real issue for an executive. Someone must own the schedule, the test setup, the rollback plan and the sign-off from whoever answers for the building. Without that owner, a published fix lowers no risk.
Interim steps exist for sites that cannot update yet. They include network monitoring, least-privilege accounts, intrusion detection and the vendor's hardening guide. Johnson Controls is open about their limits. They help, but the flaw may remain.
Questions to put to your team
Ask whether you run EasyIO Neo EC or CW controllers, and on which firmware versions. Facilities and IT may each assume the other keeps that list.
Ask who can physically reach the debug ports. Ask whether the network watches traffic to and from these devices. Ask where a firmware update would be tested before it reaches a live building.
Your Johnson Controls representative or an authorized EasyIO distributor is the route to the update. Step-by-step guidance sits in the vendor's advisory, JCI-PSA-2026-20.
A fixed version is only a partial answer. A patched building needs a person who can say when the update will be applied.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





