← All Advisories

CVE-2026-34494

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-34494

Key Details

CVECVE-2026-34494
CVSS Score / Version7.2 (High) / CVSS v4.0
Updated2026-10-02
Affected productsJohnson Controls Neo Series MVP2
Classified asCWE-1191 (On-Chip Debug and Test Interface With Improper Access Control)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsNeo Series MVP2
SubsystemsGeneral OT
SectorsMultiple

What to Know

- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.

This issue affects Neo Series MVP2: before 3.3b63. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-34494
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-34494