← All Advisories

CVE-2026-71452

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-71452

Key Details

CVECVE-2026-71452
CVSS Score / Version7.2 (High) / CVSS v4.0
Updated2026-10-02
Affected productsJohnson Controls EasyIO FS32
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsEasyIO FS32
SubsystemsGeneral OT
SectorsMultiple

What to Know

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.

This issue affects EasyIO FS32: before 3.0b63. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-71452
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-71452