Skip to content

Security1 publisher2 min readPublished

Two local-only flaws expose Johnson Controls EasyIO FG devices to full unauthorized access

CISA says two flaws in Johnson Controls EasyIO FG firmware 2.0b52 and earlier can give an attacker full access to the device. The agency rates both as hard to exploit and not remotely reachable, so the risk is with whoever can already get onto the unit's network.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Two local-only flaws expose Johnson Controls EasyIO FG devices to full unauthorized access
Generated illustration

What happened

  • CISA published the advisory on 6 October 2026 and tracks the two flaws as CVE-2026-27872 and CVE-2026-27873.
  • CISA said no public exploitation specifically targeting either flaw had been reported to it at the time of release.
  • The agency lists the product in critical manufacturing, commercial facilities, government services and facilities, transportation systems and energy, deployed worldwide.
  • Gabriele Gardois, Zachary Bushell and Lorenzo De Carli of the University of Calgary reported the flaws to Johnson Controls.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision OT teams working through this advisory have to check which internal segments, contractor links and office machines can reach EasyIO FG units, because an internet exposure scan will not find the path these flaws use.
  • exposure In the five listed sectors, operators that run office IT and control devices on one shared network give any compromised office machine a route to these units.
  • cost The response is an inventory and a segmentation review on a normal change schedule, since CISA asks for impact analysis first and reports no exploitation.

These two flaws are rated by who can reach the device. CISA says neither one can be exploited remotely [4]. An attacker has to get onto the device's local network, or reach the device itself, before either flaw can be used [11]. Getting there is only the first step, because the agency also rates the attack complexity as high [5].

An attacker who clears both bars gets the whole device [3]. The advisory lists the two CVE numbers and the affected range, firmware 2.0b52 and earlier, but it does not describe either flaw or name a fixed release [2]. For now the defences are about where the device sits on the network.

CISA's recommended practices are its standard set for control systems. Keep devices off the internet. Put control networks behind firewalls and isolate them from business networks. Use a VPN when remote access is required [9]. These flaws have no remote path, so the isolation step is the one that targets how an attack would actually arrive [11]. Taking a unit off the internet is still sound hygiene. It does not stop someone who is already on the site network [11]. The agency also tells operators to run an impact analysis and risk assessment before they deploy any of these measures [10].

The disclosure came from university researchers working with the vendor [8]. That shapes the triage call. A local-only, high-complexity bug like this ranks behind internet-reachable flaws that attackers are already using.

What to watch

  • Johnson Controls publishing its own advisory with a fixed EasyIO FG firmware release and descriptions of the two flaws.
  • A public proof of concept, or an exploitation report to CISA, for CVE-2026-27872 or CVE-2026-27873.
  • Scores or weakness classes on the CVE records showing whether an attacker needs adjacent network access or physical access.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories