Published on October 1, 2026, the advisory reports that CVE-2026-64893 may allow interception of sensitive information, including credentials and session data sent over the network. The alert assigns the vulnerability a CVSS 3 score of 5.4. Affected controllers are EC V3.3b62 and V3.3b63, and CW V3.3b24 and V3.3b25. EasyIO Neo is a programmable controller used in building automation, including HVAC, lighting, and energy systems.
Johnson Controls has issued fixes: firmware EC V3.3b64 and CW V3.3b26, or later versions. The advisory recommends assessing operational impact, backing up configurations, and testing updates before production deployment, in line with change procedures. If an update cannot be made immediately, it recommends enabling HTTPS/TLS, disabling HTTP, and limiting exposure through network segmentation, a firewall, and VPN for remote access. Consult the original CISA advisory and the CSAF summary to verify details and confirm current guidance.