Which Johnson Controls EasyIO Neo Series EC and CW Controller versions are affected by CVE-2026-64892 and CVE-2026-64893?

CISA’s October 01, 2026 advisories identify specific Johnson Controls EasyIO Neo Series EC and CW Controller versions as affected.
The affected versions
The listed affected versions are:
| Product | Affected versions |
|---|---|
| EasyIO Neo Series EC Controllers | V3.3b62, V3.3b63 |
| CW Controllers | V3.3b24, V3.3b25 |
CISA lists those same EC and CW controller versions for both CVE-2026-64892 and CVE-2026-64893.
Which issues apply
The advisories describe two separate issues:
- CVE-2026-64892: sensitive information exposure to an unauthorized actor, CVSS v3 score 3.5
- CVE-2026-64893: cleartext transmission of sensitive information, with possible interception of credentials and session data, CVSS v3 score 5.4
What to check
If your inventory includes any of the versions above, compare the device details against the official CISA advisories. The advisories identify worldwide deployment and list the company headquarters location as Ireland.
Because advisory pages can be updated, use CISA’s current notices when confirming whether a device remains in scope.
What should operators do if they use EasyIO Neo Series EC Controllers V3.3b62 or V3.3b63, or CW Controllers V3.3b24 or V3.3b25?

If you operate one of the EasyIO Neo Series versions named by CISA, the first step is to confirm whether your controller matches the affected list.
Start with the version check
CISA lists these versions as affected:
- EasyIO Neo Series EC Controllers V3.3b62 and V3.3b63
- CW Controllers V3.3b24 and V3.3b25
The listed versions are tied to both CVE-2026-64892 and CVE-2026-64893.
Understand the risk being flagged
CISA describes CVE-2026-64892 as exposure of sensitive information to an unauthorized actor.
CISA describes CVE-2026-64893 as cleartext transmission of sensitive information. The advisory context says credentials and session data could be intercepted.
That means operators should treat the issue as an information-exposure concern, especially where credentials or active session data may be involved.
Where to go next
The provided context does not include a patch version, mitigation command, deadline, or required operational procedure. Use the CISA advisories as the official reference for current vendor and mitigation details before making changes to production systems.
How do CVE-2026-64892 and CVE-2026-64893 differ for EasyIO Neo Series controllers?
CVE-2026-64892 and CVE-2026-64893 affect the same listed EasyIO Neo Series EC and CW Controller versions, but CISA describes different sensitive-information risks.
The short comparison
| Item | CVE-2026-64892 | CVE-2026-64893 |
|---|---|---|
| Affected EC versions | V3.3b62, V3.3b63 | V3.3b62, V3.3b63 |
| Affected CW versions | V3.3b24, V3.3b25 | V3.3b24, V3.3b25 |
| CISA description | Sensitive information exposure to an unauthorized actor | Cleartext transmission of sensitive information |
| Specific data mentioned | Not specified in the provided context | Credentials and session data could be intercepted |
| CVSS v3 score | 3.5 | 5.4 |
What the difference means
The first advisory is about unauthorized access to sensitive information. The second is about sensitive information being sent in cleartext, with credentials and session data named as possible intercepted information.
The provided context does not give deeper exploit mechanics or mitigation details for either CVE. For current technical guidance, check the CISA pages directly.
What sensitive information risks are described in the CISA advisories for EasyIO Neo Series controllers?

CISA’s EasyIO Neo Series advisories focus on sensitive information risks in specific EC and CW Controller versions.
What information risk is described
CISA identifies two related issues:
- CVE-2026-64892: sensitive information may be exposed to an unauthorized actor.
- CVE-2026-64893: sensitive information may be transmitted in cleartext.
For CVE-2026-64893, the context specifically mentions possible interception of credentials and session data.
Which controller versions are involved
The advisories list these versions:
- EasyIO Neo Series EC Controllers V3.3b62 and V3.3b63
- CW Controllers V3.3b24 and V3.3b25
CISA lists worldwide deployment and identifies the company headquarters location as Ireland.
What is not confirmed here
The provided context does not say which exact credentials or session data could be exposed, whether exploitation has occurred, or what replacement versions are available.
Because this is operational security information, confirm the latest details in CISA’s advisories before deciding on response steps.
Sources / Learn more
Related reading
- Why do the provided sources for 2027 Men’s College World Series point to CISA advisories instead of sports coverage?; Which Johnson Controls EasyIO controller versions are named in the October 1, 2026 CISA advisories?
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- Should you watch Netflix’s Dark before HBO’s It: Welcome to Derry season 2?
- How does Justin Herbert’s postseason record compare to Jalen Hurts’, and does that gap undercut Dan Orlovsky’s case for praising Herbert’s game over Hurts’?

Leave a Reply