Skip to content
Security & Trust

Johnson Controls patches a data-exposure flaw in building controllers

CISA says EasyIO Neo EC and CW firmware could expose sensitive data to an attacker. A fix exists; test it first.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Johnson Controls patches a data-exposure flaw in building controllers

AI-generated image for WebPulse. About our images

In brief
  • CISA reports a sensitive-data exposure flaw, CVE-2026-64892, in Johnson Controls EasyIO Neo EC and CW controllers. Fixed firmware is available, and no public exploitation has been reported to CISA.
  • The advisory asks users to test updates and follow change and safety procedures first, so the patch is a planned project in a live building.
  • Find out whether you run affected firmware, who can reach the debug ports, and who owns the update schedule.

A building cannot restart like a web server

Web teams can often patch and restart a server quickly. A building controller is harder. It helps run heating, lighting and energy use in a workplace that people are using. The lesson here is that in operational technology, the patch is the short part of the job. The long part is choosing when a running building can take it.

Owners of Johnson Controls EasyIO Neo EC and CW controllers now face that choice. CISA, the US cyber agency, published an advisory on October 1, 2026.

What CISA reported

The flaw is tracked as CVE-2026-64892. CISA says a successful attacker could gain access to sensitive information. That information could then be used to conduct further attacks against the system.

The weakness type is CWE-200. In plain terms, information reaches a person who should not see it.

Four firmware versions are affected. On EC controllers, they are V3.3b62 and V3.3b63. On CW controllers, they are V3.3b24 and V3.3b25.

Johnson Controls has released repaired firmware. EC units should move to V3.3b64 or later. CW units should move to V3.3b26 or later.

Gabriele Gardois reported the flaw to Johnson Controls. CISA says it has no report of public exploitation aimed at this flaw so far.

EC V3.3b64 / CW V3.3b26
Fixed firmware
Source: CISA advisory ICSA-26-274-04 (October 1, 2026)
None at this time
Known public exploitation reported to CISA
Source: CISA advisory ICSA-26-274-04 (October 1, 2026)

What these controllers do

CISA describes the EC and CW as programmable edge controllers for building automation. They run building functions such as heating and cooling, lighting and energy use. They link to other equipment through BACnet and Modbus. These are shared protocols that let gear from different makers work together.

CISA files the devices under five infrastructure sectors. They are critical manufacturing, commercial facilities, government, transportation and energy. The advisory does not say how many devices are in use.

What the advisory leaves out

The advisory does not explain how the exposure works. It also gives no severity score in its text. That limits what a leader can conclude about the flaw.

The interim steps offer a hint. They tell users to keep unauthorised people away from device debug ports. They also suggest firmware that turns off debug interfaces or demands a login first. Debug access may therefore matter to the risk. The advisory does not say the flaw sits there, so this is an inference.

One more point stands out. A data leak is often a first step, not the final damage. CISA's own wording points that way, since it says the data could support further attacks.

Why the fix is a project, not a click

CISA and Johnson Controls say to upgrade once operations allow. Before that, check what the change will do to the running site. Save the current settings. Try the update on a test system if you can. Follow your own change and safety rules.

That is the real issue for an executive. Someone must own the schedule, the test setup, the rollback plan and the sign-off from whoever answers for the building. Without that owner, a published fix lowers no risk.

Interim steps exist for sites that cannot update yet. They include network monitoring, least-privilege accounts, intrusion detection and the vendor's hardening guide. Johnson Controls is open about their limits. They help, but the flaw may remain.

Questions to put to your team

Ask whether you run EasyIO Neo EC or CW controllers, and on which firmware versions. Facilities and IT may each assume the other keeps that list.

Ask who can physically reach the debug ports. Ask whether the network watches traffic to and from these devices. Ask where a firmware update would be tested before it reaches a live building.

Your Johnson Controls representative or an authorized EasyIO distributor is the route to the update. Step-by-step guidance sits in the vendor's advisory, JCI-PSA-2026-20.

A fixed version is only a partial answer. A patched building needs a person who can say when the update will be applied.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-64892
Share this insight