[Control Systems] Johnson Controls security advisory (AV26-991)
Canada's Cyber Centre warns of vulnerabilities in Johnson Controls EasyIO controllers and urges updates.
On October 2, 2026, the Canadian Centre for Cyber Security issued advisory AV26-991 on Johnson Controls control-system products. As of October 1, 2026, affected versions include EasyIO FG before 2.0b52, EasyIO Neo before 3.3b63 and 3.3b25, and EasyIO FS32 before 3.0b63 and 3.3b63. The centre urges administrators to review Johnson Controls product security advisories and install updates as they become available. No CVE identifiers or observed exploitation are included.
38