Canada and CISA flag Johnson Controls EasyIO and Illustra flaws; end-of-life EasyIO FG will not be patched
Three advisories between October 2 and 7, 2026 cover Johnson Controls vulnerabilities, including hard-coded-credential flaws (CVE-2026-27872, CVE-2026-27873, CVSS 7.7) in end-of-life EasyIO FG controllers that will never receive a firmware fix.
Between October 2 and October 7, 2026, Canada's Cyber Centre and CISA published three advisories on Johnson Controls control-system and camera products. Canada's advisory AV26-991 (October 2) listed EasyIO FG before 2.0b52, EasyIO Neo before 3.3b63 and 3.3b25, and EasyIO FS32 before 3.0b63 and 3.3b63 as affected, and urged administrators to install Johnson Controls updates as they become available. CISA's October 6 advisory conflicts with that expectation for the FG line: EasyIO FG firmware 2.0b52 and earlier, which has been end-of-life and end-of-support and unsold since before 2019, contains hard-coded credential and improper privilege management flaws (CVE-2026-27872 and CVE-2026-27873), each scored CVSS 7.7 and requiring local access with high attack complexity, that could give an attacker full device access. CISA states no firmware fix will be issued and instead advises migrating to EasyIO Neo and keeping devices off the internet on segmented building-automation networks. Separately, Canada's advisory AV26-1010 (October 7) covers a vulnerability in Johnson Controls Illustra Standard - L4L China affecting versions before 6.0.0.66394, providing no CVE identifier, severity rating, or exploitation status. None of the three advisories reports active exploitation.
- Canada's Cyber Centre advisory AV26-991 was published on 2026-10-02, covering EasyIO FG before 2.0b52, EasyIO Neo before 3.3b63 and 3.3b25, and EasyIO FS32 before 3.0b63 and 3.3b63, and urging administrators to apply updates as they become…
- CISA's advisory, published 2026-10-06, states EasyIO FG firmware 2.0b52 and earlier is affected by CVE-2026-27872 and CVE-2026-27873 (hard-coded credentials and improper privilege management), both scored CVSS 7.7 and requiring local…
- The EasyIO FG series is end-of-life and end-of-support and has been unsold since before 2019; CISA says no firmware fix will be issued and advises migrating to EasyIO Neo and isolating devices on segmented building-automation networks.
- Canada's Cyber Centre advisory AV26-1010 was published on 2026-10-07, covering Johnson Controls Illustra Standard - L4L China versions before 6.0.0.66394, with no CVE, severity rating, or exploitation information provided.
- Sources disagree on patching the EasyIO FG line: Canada's AV26-991 urges installing vendor updates, while CISA states no patch will be issued because the series is end-of-life.
- No advisory reports active exploitation of any of the vulnerabilities.
Coverage timelineoldest first · each row is one article
- · 6d ago[Control Systems] Johnson Controls security advisory (AV26-991)
Canadian Centre for Cyber Security· 38
Canada's Cyber Centre warns of vulnerabilities in Johnson Controls EasyIO controllers and urges updates.
- · 2d agoJohnson Controls EasyIO FG
CISA Advisories· 44
CISA says end-of-life Johnson Controls EasyIO FG firmware has hard-coded credential flaws and will not be patched.
- · 1d ago[Control Systems] Johnson Controls security advisory (AV26-1010)
Canadian Centre for Cyber Security· 28
Canada's Cyber Centre alerts administrators to a Johnson Controls Illustra Standard vulnerability and urges updates.
Vulnerabilities in this storyAll →
- CVE-2026-278725.6—Improper privilege management in Johnson Controls Easy IO FGpublished · Johnson Controls Easy IO FG
- CVE-2026-278735.6—Hard-coded credentials in Johnson Controls EasyIO FGpublished · Johnson Controls EasyIO FG
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure |
|---|