Executive Summary
Johnson Controls disclosed CVE-2026-64893, a medium-severity vulnerability affecting EasyIO Neo Series EC and CW Controllers used in building automation systems worldwide. The vulnerability allows attackers to intercept sensitive information including credentials and session data transmitted in cleartext over HTTP connections. Affected versions include EC Controllers V3.3b62 and V3.3b63, and CW Controllers V3.3b24 and V3.3b25, with fixes available in V3.3b64 and V3.3b26 respectively.
This incident highlights the persistent security challenges in operational technology environments where legacy protocols and unencrypted communications remain prevalent. As building automation systems become increasingly connected and targeted by threat actors, the exposure of credentials through cleartext transmission represents a critical attack vector for lateral movement within enterprise networks.
Why This Matters Now
Building automation systems are increasingly targeted as entry points for ransomware and espionage campaigns, making the secure transmission of credentials and session data critical for preventing broader network compromise in critical infrastructure environments.
Attack Path Analysis
Attackers exploited cleartext transmission vulnerability (CVE-2026-64893) in Johnson Controls EasyIO Neo Series controllers to intercept credentials and session data via man-in-the-middle attacks. Using compromised credentials, they gained unauthorized access to building automation systems, potentially moved laterally through unencrypted HTTP communications, established persistent access through web interfaces, exfiltrated sensitive operational data, and could disrupt HVAC, lighting, and energy systems across critical infrastructure facilities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-64893 cleartext transmission vulnerability in EasyIO Neo controllers to intercept credentials and session tokens transmitted over unencrypted HTTP on port 80
Related CVEs
CVE-2026-64893
CVSS 7.3Johnson Controls EasyIO Neo Series EC and CW Controllers transmit sensitive information including credentials and session data in cleartext over the network, allowing attackers to intercept authentication data.
Affected Products:
Johnson Controls EasyIO Neo Series EC Controllers – V3.3b62, V3.3b63
Johnson Controls EasyIO Neo Series CW Controllers – V3.3b24, V3.3b25
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Network Sniffing
Adversary-in-the-Middle
Credentials In Files
SMB/Windows Admin Shares
Exploit Public-Facing Application
Code Repositories
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Cardholder Data Transmission
Control ID: 4.2.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Encrypted Network Traffic
Control ID: Network Security - Advanced
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Commercial Real Estate
Johnson Controls EasyIO building automation controllers managing HVAC and lighting systems vulnerable to credential interception, compromising tenant safety and facility operations.
Health Care / Life Sciences
Hospital HVAC and building automation systems exposed to cleartext transmission vulnerabilities, risking patient safety through compromised environmental controls and HIPAA violations.
Government Administration
Federal and municipal facilities using affected building controllers face infrastructure vulnerability risks with potential unauthorized access to critical environmental and security systems.
Higher Education/Acadamia
Campus building automation systems vulnerable to man-in-the-middle attacks, potentially disrupting educational facilities' HVAC, lighting, and energy management across multiple buildings.
Sources
- Johnson Controls EasyIO Neo Series EC and CW Controllershttps://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05Verified
- Johnson Controls Product Security Advisory JCI-PSA-2026-30https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesVerified
- Johnson Controls Trust Center Cybersecurity Resourceshttps://www.johnsoncontrols.com/trust-center/cybersecurity/resourcesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be highly relevant to this building automation attack as it could segment network access and reduce the blast radius of credential compromise across IoT and operational technology systems.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security controls would likely reduce the scope of credential interception by constraining network visibility and limiting attacker positioning for man-in-the-middle attacks across building automation segments
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the scope of compromised credentials by limiting administrative access to specific controller segments rather than broad building automation network privileges
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely reduce lateral movement capabilities by constraining inter-controller communications and limiting pivoting between different building automation system segments
Control: Multicloud Visibility & Control
Mitigation: Visibility and control mechanisms would likely detect and constrain anomalous command patterns, reducing attacker ability to maintain persistent administrative sessions across multiple building automation controllers
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration by limiting outbound communications from building automation networks and reducing the volume of operational data that could be transmitted externally
Remaining impact would likely be contained to specific building automation zones rather than facility-wide disruption, with reduced ability to affect critical infrastructure operations across multiple systems simultaneously
Impact at a Glance
Affected Business Functions
- HVAC Control Systems
- Building Automation
- Energy Management Systems
- Lighting Control
Estimated downtime: 2 days
Estimated loss: N/A
Network credentials, session tokens, and building automation system authentication data transmitted in cleartext, potentially exposing facility management access and operational control credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Encrypted Traffic (HPE) capabilities to prevent cleartext transmission of sensitive credentials and session data in building automation networks
- • Deploy Zero Trust Segmentation to isolate building automation controllers and limit lateral movement between network segments
- • Enable Multicloud Visibility & Control to monitor and detect unencrypted HTTP traffic and unauthorized access to management interfaces
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from building automation systems
- • Deploy Threat Detection & Anomaly Response capabilities to identify man-in-the-middle attacks and credential interception attempts on industrial control networks



