Johnson Controls Disclosed Vulnerability in EasyIO Controllers
The newly identified security flaw affects specific EasyIO Neo Series hardware, posing risks to unauthorized data access.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust that industrial control systems in your area are adequately protected from cyber attacks?
Johnson Controls has disclosed a security vulnerability, tracked as CVE-2026-64892, impacting its EasyIO Neo Series EC and CW controllers. The security gap, reported by researcher Gabriele Gardois, could allow an attacker to gain unauthorized access to sensitive system information.
Why it matters
Securing building management systems is critical as unauthorized access can expose sensitive operational data or compromise facility control networks. Manufacturers often issue such advisories to allow operators to mitigate risks before public exploits emerge.
The vulnerability, cataloged as CVE-2026-64892, affects EasyIO Neo Series EC controllers (versions V3.3b63 and V3.3b62) and CW controllers (versions V3.3b25 and V3.3b24). While the advisory notes potential unauthorized access to sensitive info, the specific impact on operational availability remains unknown.
The players
Johnson Controls
An Ireland-based multinational conglomerate providing building management systems, HVAC hardware, and integrated digital facility security stacks.
Gabriele Gardois
A security researcher who discovered and reported the vulnerability to the manufacturer.
The details
Attackers can leverage this vulnerability to gain unauthorized access to sensitive information stored within the controller environment. EasyIO controllers, widely used for building automation, function as the connective tissue between physical mechanical systems and digital management interfaces. The security flaw was identified and reported to the manufacturer by Gabriele Gardois.
Timeline
The vulnerability advisory was released on October 1, 2026.
The Tech Race
This disclosure follows a pattern of proactive security reporting for industrial control systems that helps administrators patch devices before they appear in the CISA Known Exploited Vulnerabilities Catalog. Early identification remains the primary defense for critical infrastructure operators against unauthorized network infiltration.
Building managers and network administrators using EasyIO Neo Series hardware should review their system versions against the specified affected models. While no public exploits have been reported, organizations should monitor for upcoming firmware updates or manufacturer security guidelines.
The takeaway
This disclosure highlights the ongoing necessity for strict firmware maintenance cycles in building automation networks. Operators should monitor the manufacturer's advisory page for official patches or configuration workarounds to address CVE-2026-64892.
Further reading
For more information on defending industrial environments, see our full coverage of Cybersecurity.
More information
Review the full details of the notification at the Johnson Controls cybersecurity hardening guidelines.
Source note: This article includes information reported by Cisa.
Live Poll
Do you trust that industrial control systems in your area are adequately protected from cyber attacks?







