Blog/vulnerabilities
vulnerabilities

Johnson Controls Inc. Airwall

August 13, 2026·Source: CISA
0 comments

TL;DR

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities

v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of Hard-coded Cryptographic Key, External Control of File Name or Path

Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64887 A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure. View CVE Details Affected Products Johnson Controls Inc. Airwall Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. Airwall: <=4.0.4 Product Status: known_affected Remediations Mitigation To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later pa

What Happened

Johnson Controls Inc. Airwall, reported by CISA.

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities

v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of Hard-coded Cryptographic Key, External Control of File Name or Path

Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64887 A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure. View CVE Details Affected Products Johnson Controls Inc. Airwall Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. Airwall: <=4.0.4 Product Status: known_affected Remediations Mitigation To help reduce risk of exploitation, Johnson Controls recommends the following defensive measures: Apply v4.1.0 or later pa

For the full technical details, see the original report.

Why It Matters for Businesses

This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.

How to Check Your Exposure

Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.

Check Your Domain Security

Mitigation Steps

  • Patch immediately, Apply vendor patches or updates as soon as they are available.
  • Review configurations, Check firewall rules, access controls, and security headers.
  • Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
  • Update security policies, Ensure incident response plans cover this type of threat.
  • Run a security scan, Use automated tools to verify your exposure.

Need Expert Help?

If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.

Need More Scan Credits?

Get up to 100 scans or unlimited lifetime access starting at $15.

View Plans →

Comments (0)

No comments yet. Be the first to comment!

← Back to Blog