[Control Systems] Johnson Controls security advisory (AV26-991)
Canada's Cyber Centre warns of vulnerabilities in Johnson Controls EasyIO controllers and urges updates.
On October 2, 2026, the Canadian Centre for Cyber Security issued advisory AV26-991 on Johnson Controls control-system products. As of October 1, 2026, affected versions include EasyIO FG before 2.0b52, EasyIO Neo before 3.3b63 and 3.3b25, and EasyIO FS32 before 3.0b63 and 3.3b63. The centre urges administrators to review Johnson Controls product security advisories and install updates as they become available. No CVE identifiers or observed exploitation are included.
- Advisory AV26-991 was published on October 2, 2026.
- EasyIO FG, Neo, and FS32 builds before listed versions are affected.
- No CVE identifiers or active exploitation are stated.
- Administrators are told to apply Johnson Controls updates when available.
Full article73 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-991
Date: October 2, 2026
As of October 1, 2026, Johnson Controls is affected by vulnerabilities in the following products:
- Easy IO FG
- Prior to 2.0b52
- Easy IO Neo
- Prior to 3.3b63
- Prior to 3.3b25
- EasyIO FS32
- Prior to 3.0b63
- Prior to 3.3b63
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/control-systems-johnson-controls-security-advisory-av26-991