Executive Summary
In August 2026, Johnson Controls Inc. disclosed two critical vulnerabilities in their Airwall product, identified as CVE-2026-64887 and CVE-2026-34492. CVE-2026-64887 involves the use of a hard-coded cryptographic key, potentially allowing attackers to decrypt sensitive data across all installations. CVE-2026-34492 is an arbitrary file read vulnerability, enabling unauthorized access to system files. Both vulnerabilities affect Airwall versions up to and including 4.0.4. Johnson Controls has released patches in version 4.1.0 to address these issues.
The disclosure underscores the persistent risks associated with hard-coded credentials and inadequate input validation in critical infrastructure systems. Organizations are urged to apply the provided patches promptly and review their security practices to prevent similar vulnerabilities.
Why This Matters Now
The vulnerabilities in Johnson Controls' Airwall product highlight the ongoing challenges in securing critical infrastructure against sophisticated cyber threats. Immediate patching and adherence to secure coding practices are essential to mitigate potential exploitation.
Attack Path Analysis
An attacker exploited hardcoded cryptographic keys in Johnson Controls Inc. Airwall to decrypt sensitive data, leading to unauthorized access and potential data exfiltration.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker exploited the hardcoded cryptographic key vulnerability (CVE-2026-64887) in Johnson Controls Inc. Airwall to decrypt sensitive data.
Related CVEs
CVE-2026-64887
CVSS 6.8A hardcoded cryptographic key in Johnson Controls Inc. Airwall versions up to 4.0.4 allows attackers to decrypt sensitive data, leading to unauthorized access.
Affected Products:
Johnson Controls Inc. Airwall – <=4.0.4
Exploit Status:
no public exploitCVE-2026-34492
CVSS 6.4An arbitrary file read vulnerability in Johnson Controls Inc. Airwall versions up to 4.0.4 allows attackers to access sensitive files on the system.
Affected Products:
Johnson Controls Inc. Airwall – <=4.0.4
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Unsecured Credentials: Private Keys
Valid Accounts
Direct Volume Access
Data from Local System
File and Directory Discovery
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Cryptographic Key Storage
Control ID: 3.5.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Security Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Building Materials
Johnson Controls Airwall vulnerabilities expose HVAC and building automation systems to hardcoded cryptographic key exploitation and unauthorized file access across facilities.
Commercial Real Estate
Critical manufacturing facilities using Johnson Controls systems face authentication bypass and data decryption risks through hardcoded keys affecting building security infrastructure.
Government Administration
Government facilities and services infrastructure vulnerable to arbitrary file read attacks and sensitive configuration data exposure through compromised Airwall systems.
Transportation
Transportation systems infrastructure faces significant authentication control bypass and unauthorized access risks through hardcoded cryptographic vulnerabilities in Johnson Controls Airwall deployments.
Sources
- Johnson Controls Inc. Airwallhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03Verified
- Johnson Controls Security Advisorieshttps://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it enforces strict segmentation and identity-aware policies, which would likely limit the attacker's ability to move laterally and exfiltrate data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial exploitation of a vulnerability, it would likely limit the attacker's ability to leverage the compromised system to access other network segments.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing least-privilege access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain the attacker's lateral movement by enforcing strict communication policies between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and limit unauthorized command and control channels by providing centralized monitoring and policy enforcement.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF would likely reduce the scope of operational disruption by limiting the attacker's access to critical systems and data.
Impact at a Glance
Affected Business Functions
- Network Security
- Data Protection
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive configuration files and cryptographic keys.
Recommended Actions
Key Takeaways & Next Steps
- • Implement a secure key management system to prevent the use of hardcoded cryptographic keys.
- • Regularly rotate cryptographic keys to limit exposure if a key is compromised.
- • Apply the principle of least privilege to restrict access to sensitive data and system resources.
- • Deploy network segmentation to limit lateral movement within the network.
- • Monitor and analyze network traffic for anomalies to detect potential command and control communications.



