Johnson Controls Inc. Airwall
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of Hard-coded Cryptographic Key, External Control of File Name or Path Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Tra
Why it matters
The weakness can enable direct compromise with limited attacker prerequisites, making internet-facing assets the first place to look.
What defenders should do
Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.
Verify at the source
CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →
Move from reading to action with the free CyberKit toolbox.