CISA alerts to cleartext data exposure in Johnson Controls EasyIO Neo controllers

Organizations using Johnson Controls EasyIO Neo EC V3.3b62/63 or CW V3.3b24/25 must address the cleartext transmission flaw disclosed on Oct. 1 2026.

an aerial view of the capital building in washington d c

The Cybersecurity and Infrastructure Security Agency (CISA) issued Product Security Advisory JCI-PSA-2026-30 on Oct. 1 2026, identifying vulnerability CVE-2026-64893 in Johnson Controls EasyIO Neo Series EC and CW controllers. The flaw permits an attacker to intercept and read sensitive information, including credentials and session data, that is transmitted in cleartext over the network.

The advisory lists the affected firmware versions as EasyIO Neo Series EC Controllers V3.3b62 and V3.3b63, and EasyIO Neo Series CW Controllers V3.3b24 and V3.3b25. The vulnerability is assigned a CVSS v3 base score of 5.4 and maps to CWE-319 (Cleartext Transmission of Sensitive Information). Deployments span worldwide and support critical infrastructure sectors such as critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy.

CISA recommends that users of the affected controllers implement defensive measures, conduct impact analyses, and perform risk assessments before deploying mitigations. Organizations are urged to follow the control systems security recommended practices on the CISA ICS webpage and to consult the technical information paper ICS-TIP-12-146-01B for targeted intrusion detection and mitigation strategies. Reports of suspected malicious activity should be routed through internal procedures and forwarded to CISA for tracking.

To date, CISA has not observed public exploitation of CVE-2026-64893, though the advisory notes a high attack complexity. The agency continues to monitor the situation and provides additional mitigation guidance on its website.

Keep reading