Johnson Controls Inc. Airwall
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of Hard-coded Cryptographic Key, External Control of File Name or Path Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64887 A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure. View CVE Details Affected Products Johnson Controls Inc. Airwall Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. Airwall: <=4.0.4 Product Status: known_affected Remediations Mitigation To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later patches fo
CSIRTS triage
- What
- Hard-coded cryptographic key and path traversal vulnerabilities allowing decryption of sensitive data and arbitrary file read access.
- Who is affected
- Airwall deployments version 4.0.4 and earlier.
- Urgency
- Critical; hard-coded credentials and file read vulnerabilities directly threaten deployment security.
- Action
- Upgrade to Airwall version newer than 4.0.4 or apply vendor patch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Airwall
Get an email when a new Airwall advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-648870.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-344920.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64887 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34492 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Johnson Controls Inc
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalJohnson Controls Inc. TL280cisa · 2026-08-06
More from CISA Cybersecurity Advisories
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalANDRITZ HIPASE-250 and 250 SCALA2026-08-13
- criticalJohnson Controls Metasys2026-08-13