Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Hardcoded Cryptographic Key in Johnson Controls Airwall (CVE‑2026‑64887, CVE‑2026‑34492) Enables Authentication Bypass and Data Decryption

Johnson Controls Airwall versions ≤ 4.0.4 embed a universal cryptographic key, allowing attackers to decrypt data, bypass authentication, and read arbitrary files. For SOC 2 auditors, the flaw highlights the need for unique key management and continuous evidence of access‑control remediation.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
5 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Hardcoded Cryptographic Key in Johnson Controls Airwall (CVE‑2026‑64887, CVE‑2026‑34492) Enables Authentication Bypass and Data Decryption

What It Is — The Airwall application embeds a hard‑coded password/cryptographic key that is identical across every deployment. Possession of the key lets an attacker decrypt configuration and database files, bypass authentication, and read arbitrary files on the system.

Exploitability — No public exploit code has been released, but the vulnerability carries a CVSS 3.0 score of 6.8 (High) and can be leveraged by any actor who can obtain the binary or source code.

Affected Products — Johnson Controls Inc. Airwall versions ≤ 4.0.4 (CVE‑2026‑64887, CVE‑2026‑34492).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control criteria demand unique, managed credentials; a hard‑coded key violates this and makes it impossible to prove “least‑privilege” during an audit.
  • Continuous evidence of key‑management (secure storage, rotation, per‑device uniqueness) is required to satisfy the CC6.1 and CC6.2 controls in the SOC 2 Trust Services Criteria.
  • Demonstrating remediation (patching, KMS/HSM usage) provides audit‑ready proof that the organization is actively managing a critical security control, a factor increasingly demanded by enterprise customers.

Recommended Actions

  • Patch all Airwall installations to v4.1.0 or later.
  • Migrate every cryptographic key to a dedicated KMS/HSM; remove hard‑coded keys from source code and binaries.
  • Establish a documented key‑rotation policy with a defined rotation interval and enforce unique keys per device/installation.
  • Update SOC 2 access‑control policies to reflect the new key‑management process and capture the change in your continuous‑control monitoring system as audit evidence.

Source: CISA Advisory ICSA‑26‑225‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →