VulnSea

Johnson Controls has 12 CVEs on record. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 12. The median CVSS is 5.9 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: EasyIO FS32 (7), Easy IO FG (1), Easy IO Neo (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
—
Last 90 days
12 prev 0

Products

  • EasyIO FS32 7
  • Easy IO FG 1
  • Easy IO Neo 1
  • EasyIO FG 1
  • EasyIO NEO 1
  • Neo Series MVP2 1
12
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Johnson Controls vulnerabilities

CVEs affecting Johnson Controls, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-71453Medium· 5.6
today

- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.

- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.

▾ SunlitJohnson Controls · EasyIO FS32via NVD
CVE-2026-71452High· 7.2
today

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.

▾ TwilightJohnson Controls · EasyIO FS32via NVD
CVE-2026-71449Critical· 9.3
today

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.

▾ MidnightJohnson Controls · EasyIO FS32via NVD
CVE-2026-71448Medium· 5.6
today

: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.

: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.

▾ SunlitJohnson Controls · EasyIO FS32via NVD
CVE-2026-64893High· 7.3
today

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.

▾ TwilightJohnson Controls · EasyIO NEOvia NVD
CVE-2026-64892Medium· 6.3
today

- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.

- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.

▾ SunlitJohnson Controls · Easy IO Neovia NVD
CVE-2026-34494High· 7.2
today

- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.

- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.

▾ TwilightJohnson Controls · Neo Series MVP2via NVD
CVE-2026-34493High· 7.2
today

- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.

- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.

▾ TwilightJohnson Controls · EasyIO FS32via NVD
CVE-2026-27873Medium· 5.6
today

- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.

- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.

▾ SunlitJohnson Controls · EasyIO FGvia NVD
CVE-2026-71451Medium· 5.6
today

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.

▾ SunlitJohnson Controls · EasyIO FS32via NVD
CVE-2026-27874Medium· 5.0
today

: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.

: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.

▾ SunlitJohnson Controls · EasyIO FS32via NVD
CVE-2026-27872Medium· 5.6
today

- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.

- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.

▾ SunlitJohnson Controls · Easy IO FGvia NVD
Johnson Controls vulnerabilities (CVEs) · VulnSea