CVE-2026-64892

N/A

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The...

Affects 0 products across 1 vendor.

PatchUnknown
◆ AI Analysis — automated analysis, not human-reviewed

A unscored severity vulnerability (CVE-2026-64892) affects the target system. View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Se...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-64892?
A unscored severity vulnerability (CVE-2026-64892) affects the target system. View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Se...
Is CVE-2026-64892 actively exploited?
No confirmed active exploitation of CVE-2026-64892 as of 2026-10-02.
How do I remediate CVE-2026-64892?
Apply vendor patches for CVE-2026-64892. Monitor Johnsoncontrols advisories.
What systems are affected by CVE-2026-64892?
CVE-2026-64892 affects: Johnsoncontrols.
Vulnerability Details
CVE IDCVE-2026-64892
Published2026-10-01
Last Modified2026-10-01
ICS Relevance0%
SourceCISA
Official Description

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Johnsoncontrols — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 0 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Johnsoncontrols
CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2021-27664 9.8 Under certain configurations an unauthenticated remote user could be given ac... CVE-2019-7589 9.8 A vulnerability with the SmartService API Service option exists whereby an un... CVE-2021-27663 9.8 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems...
View all Johnsoncontrols CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →