Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

CISA Advisory: CVE‑2026‑64892 in Johnson Controls EasyIO Neo Controllers Exposes Sensitive Information

CISA has warned that Johnson Controls EasyIO Neo EC and CW controllers (CVE‑2026‑64892) contain a flaw that may allow unauthorized actors to retrieve sensitive configuration data, potentially enabling further attacks on building‑automation systems. The issue tests the control objective of secure configuration and continuous monitoring, impacting audit readiness across multiple compliance frameworks.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

CVE‑2026‑64892 in Johnson Controls EasyIO Neo EC & CW Controllers Exposes Sensitive Information

What It Is — CISA issued an advisory for a vulnerability (CVE‑2026‑64892) in Johnson Controls EasyIO Neo Series EC and CW programmable edge controllers. The flaw could let an unauthenticated actor retrieve sensitive configuration data that may be leveraged for further attacks on building‑automation networks.

Exploitability — No public exploit code has been released, but the advisory confirms successful exploitation is feasible. CVSS v3.1 base score 3.5 (moderate).

Affected Products — Johnson Controls EasyIO Neo Series:

  • EC Controllers V3.3b62, V3.3b63
  • CW Controllers V3.3b24, V3.3b25

Why It Matters for Trust & Control Assurance

  • Secure Configuration & Patch Management – The issue tests the control objective of maintaining hardened, up‑to‑date OT assets, a core evidence point for audit‑ready programs across frameworks.
  • Continuous Asset Visibility – Demonstrates the need for an inventory that feeds into real‑time monitoring, proving due‑diligence to regulators and enterprise buyers.
  • Defensible Evidence – A single unpatched controller can erode the trust posture of an entire facility; continuous logging and evidence collection become essential to show control effectiveness.

Recommended Actions

  • Inventory all EasyIO Neo EC/CW controllers and confirm firmware versions against the list above.
  • Apply Johnson Controls‑provided patches or upgrade to the latest firmware immediately.
  • Feed controller inventory and patch status into a continuous control‑monitoring platform.
  • Enable detailed logging on each device and forward logs to a centralized SIEM for anomaly detection.
  • Conduct a risk assessment of downstream systems that could be compromised using the exposed configuration data.

Source: CISA Advisory

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →