[Control Systems] Johnson Controls security advisory (AV26-837)
Serial Number: AV26-837 Date: August 19, 2026 As of August 13, 2026, Johnson Controls is affected by vulnerabilities in the following products: Airwall Prior to 4.1.0 Metasys 12 all versions Metasys 13 all versions Metasys 14 all versions prior to v14.1.5 Metasys 15 all versions prior to v15.0.1 TL280 Prior to v5.62 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Johnson Controls - Product Security Advisories
CSIRTS triage
- What
- Multiple unspecified vulnerabilities in Airwall, Metasys, and TL280 products.
- Who is affected
- Johnson Controls customers using Airwall, Metasys (versions 12-15), and TL280 control systems.
- Urgency
- Moderate; specific vulnerability details not disclosed; control system impact requires attention.
- Action
- Apply vendor-supplied updates: Airwall to 4.1.0+, Metasys 14 to 14.1.5+, Metasys 15 to 15.0.1+, TL280 to 5.62+.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-johnson-controls-security-advisory-av26-837
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24