← All Advisories

CVE-2026-71449

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-71449

Key Details

CVECVE-2026-71449
CVSS Score / Version9.3 (Critical) / CVSS v4.0
Updated2026-10-02
Affected productsJohnson Controls EasyIO FS32
Classified asCWE-321 (Use of Hard-coded Cryptographic Key)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsEasyIO FS32
SubsystemsGeneral OT
SectorsMultiple

What to Know

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.

This issue affects EasyIO FS32: before 3.0b63. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-71449
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-71449