Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Cleartext Credential Exposure Vulnerability (CVE-2026-64893) in Johnson Controls EasyIO Neo Controllers

CISA has flagged CVE‑2026‑64893 in Johnson Controls EasyIO Neo EC and CW controllers, where credentials and session data travel unencrypted. The flaw affects devices deployed worldwide in critical manufacturing, commercial facilities, government services, transportation and energy sectors, creating a potential data‑exposure risk that auditors will scrutinize under control‑assurance programs.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
5 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Cleartext Credential Exposure Vulnerability (CVE‑2026‑64893) in Johnson Controls EasyIO Neo Controllers

What It Is — The EasyIO Neo Series EC and CW edge controllers transmit credentials and session data in cleartext over the network. The flaw is tracked as CVE‑2026‑64893 and has a CVSS v3 base score of 5.4 (moderate).

Exploitability — No public exploit has been observed, but the vulnerability is exploitable by any adversary with network access to the controller.

Affected Products — Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63 and CW Controllers V3.3b24, V3.3b25.

Why It Matters for Trust & Control Assurance

  • Encryption in transit is a core control that spans multiple frameworks; lacking it leaves a gap in data‑in‑motion protection and audit evidence.
  • Continuous monitoring of network traffic and logging of credential use provides the defensible trail auditors expect.
  • Demonstrating that this control is enforced (e.g., TLS‑protected APIs) signals to enterprise buyers that the building‑automation supply chain is trustworthy.

Recommended Actions

  • Enable TLS or an equivalent encrypted channel on all EasyIO Neo controllers.
  • Update firmware to the vendor‑released patch that addresses CVE‑2026‑64893.
  • Validate that all management traffic is captured in a centralized log and that logs are retained per your audit policy.
  • Map the “encrypted transmission of sensitive data” requirement to your control framework of record and capture remediation evidence.

Source: CISA Advisory – ICSA‑26‑274‑05

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →