Published on October 1, 2026, the advisory reports that CVE-2026-64892 may allow unauthorized access to sensitive information that could be useful in further attacks. Its stated rating is CVSS v3 3.5. The devices are edge controllers for building automation, including HVAC, lighting, and energy management, with BACnet and Modbus support; the advisory identifies critical-infrastructure sectors and worldwide deployment.
Affected models are EasyIO Neo Series EC controllers V3.3b62 and V3.3b63, and CW controllers V3.3b24 and V3.3b25. The advisory lists fixes in firmware EC V3.3b64 and CW V3.3b26. It recommends updating to a fixed version or later as soon as operationally feasible, after consulting a Johnson Controls representative or authorized EasyIO distributor.
Before updating production ICS/OT systems, assess operational impact, back up relevant configurations, test in a non-production environment when feasible, and follow applicable change-management and security procedures. If an update cannot happen immediately, the advisory recommends physically restricting access to device debug ports and monitoring network traffic to and from the devices for unusual or unauthorized access.
To verify scope, versions, and recommendations, consult the CISA ICS advisory identified as ICSA-26-274-04, compare it with the CSAF summary, and check the vendor’s guidance. Confirm installed firmware and local procedures before acting: a feed translation may not reproduce the original in full. If using AI to study the advisory or prepare a plan, share only the necessary excerpt and remove names, credentials, addresses, and network details.