CVE-2026-27874

N/A

: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.

Affects 0 products across 1 vendor.

CVSS v45.0
EPSS0.1%
Percentile2th
PatchUnknown
CWE Weakness Definitions
CWE-798: Use of Hard-Coded Credentials

Software contains embedded passwords or keys that cannot be changed by the administrator.

Related Attack Patterns (CAPEC)
CAPEC-70 Try Common or Default Usernames and Passwords
via CWE-798
CAPEC-191 Read Sensitive Constants Within an Executable
via CWE-798

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A unscored severity vulnerability (CVE-2026-27874) affects the target system. : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-27874?
A unscored severity vulnerability (CVE-2026-27874) affects the target system. : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
Is CVE-2026-27874 actively exploited?
No confirmed active exploitation of CVE-2026-27874 as of 2026-10-06.
How do I remediate CVE-2026-27874?
Apply vendor patches for CVE-2026-27874. Monitor Johnsoncontrols advisories.
What systems are affected by CVE-2026-27874?
CVE-2026-27874 affects: Johnsoncontrols.
Vulnerability Details
CVE IDCVE-2026-27874
Published2026-10-01
Last Modified2026-10-02
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Johnsoncontrols — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 4 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Johnsoncontrols
CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-27664 9.8 Under certain configurations an unauthenticated remote user could be given ac... CVE-2019-7589 9.8 A vulnerability with the SmartService API Service option exists whereby an un... CVE-2021-27663 9.8 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems...
View all Johnsoncontrols CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →