Johnson Controls EasyIO Neo EC and CW controllers on four V3.3 builds transmit credentials and session data in cleartext, tracked as CVE-2026-64893. Anyone who can see the management traffic can lift a login to a building's HVAC, lighting and energy controls.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence70
CISA published nine flaws in Anjvision's YSSD-RTMP-H5 firmware with no fix planned, saying the vendor has not answered its requests. Owners have no patch to wait for and must isolate the devices or replace them.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence65
Siemens ProductCERT reported the traversal itself, and fixed builds are out for four SIMOVE Fleetmanager branches and SIPLANT V3.1. For SIPLANT V1.7, V2.2 and V3.0 the advisory's remedy is an email to support.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence72
CVE-2026-12663 covers every ControlFLASH build through V15.07, where any local account on an engineering workstation could stage code that runs with the privileges of the next engineer to open the firmware updater.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap−8
- Incentives34
- Confidence70
CISA lists the fuel-management product's affected versions as a PHP release rather than any Fuel-Boss build, which tells asset owners in defense, manufacturing and transport that their patch list is keyed to the wrong field.
Reality
- Evidence68
- Adoption32
- Hype gap−8
- Incentives28
- Confidence64
CVE-2026-64629 is an out-of-bounds read in Siemens' Parasolid, triggered by reading a file. The remediation is a version bump on two separate branches, with no listed workaround.
Reality
- Evidence70
- Adoption22
- Hype gap+8
- Incentives58
- Confidence68