CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-27871

criticalcovered by 1 sourcefirst seen 2026-08-06
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63 CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27871 Hardcoded credentials refer to usernames, passwords, or other authentication information that are embedded directly into the source code of a firmware file. These credentials are often used to access system login and other areas of an application. View CVE Details Affected Products Johnson Controls Inc. TL280 Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. TL280: <5.63 Product Status: known_affected Remediations Vendor fix To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63. Mitigation Johnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments. Mitigation Monitor device access logs for any anomalous authentication activity. Mitigation Rotate any shared or downstream credentials that may have been derived from or associated with the hard-coded values. Mitigation Implement network segmentation and place ICS/SCADA devices and systems behind firewalls, isolating them from the business network. Mitigation When remote access is required, use secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be kept up to date. Mitigatio

CSIRTS triage

What
Hardcoded credentials embedded in firmware allow unauthenticated access to the device.
Who is affected
TL280 devices running versions below 5.63 deployed in critical manufacturing, energy, transportation, and government facilities worldwide.
Urgency
Critical urgency; hardcoded credentials provide direct authentication bypass and unauthorized access to sensitive systems.
Action
Upgrade TL280 firmware to version 5.63 or later immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-27871

Get an email if CVE-2026-27871 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-27871

CVE.org record

Embed the live status

CVE-2026-27871 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-27871 status](https://www.csirts.com/badge/CVE-2026-27871)](https://www.csirts.com/cve/CVE-2026-27871)