Which EasyIO FG firmware versions are affected by CISA advisory ICSA-26-279-01?

CISA’s advisory identifies the affected Johnson Controls EasyIO FG product as firmware version 2.0b52 and earlier.
The affected versions
If an EasyIO FG device is running firmware version 2.0b52 or any earlier version, it falls within the affected range described in CISA advisory ICSA-26-279-01.
The advisory names two CVEs:
- CVE-2026-27872
- CVE-2026-27873
Why version checking matters
CISA says successful exploitation could give an attacker full unauthorized device access. The advisory describes the issues as hard-coded credentials and improper privilege management.
Who should pay attention
CISA lists affected sectors including critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy.
For the latest vendor or agency guidance, check the current CISA advisory before making operational decisions.
What should operators do if they run Johnson Controls EasyIO FG firmware version 2.0b52 or earlier?

If your Johnson Controls EasyIO FG device runs firmware version 2.0b52 or earlier, CISA’s advisory places it in the affected range.
First steps for operators
Start with confirmation, not assumptions:
- Check the EasyIO FG firmware version.
- Compare it with CISA’s affected range: version 2.0b52 and earlier.
- Review CISA advisory ICSA-26-279-01 for the current official guidance.
- Treat the issue as significant because CISA says exploitation could allow full unauthorized device access.
What the advisory says is involved
CISA identifies two vulnerabilities, CVE-2026-27872 and CVE-2026-27873. The issues are described as involving hard-coded credentials and improper privilege management.
Sectors named by CISA
The advisory lists several affected sectors, including critical manufacturing, commercial facilities, government services and facilities, transportation systems, and energy.
Because ICS advisories can be updated, use the live CISA page as the source for any remediation details.
What changed in the October 06, 2026 CISA advisory for Johnson Controls EasyIO FG?

CISA published ICS advisory ICSA-26-279-01 for Johnson Controls EasyIO FG on October 06, 2026.
What the advisory added
The advisory identifies EasyIO FG firmware version 2.0b52 and earlier as affected.
It also lists two vulnerabilities:
- CVE-2026-27872
- CVE-2026-27873
What the vulnerabilities involve
CISA describes the issues as involving hard-coded credentials and improper privilege management. The stated possible result is full unauthorized device access after successful exploitation.
Which sectors are named
CISA lists affected sectors including:
- critical manufacturing
- commercial facilities
- government services and facilities
- transportation systems
- energy
The advisory page should be checked directly for any later changes or additional mitigation details.
Sources / Learn more
Related reading
- Which Johnson Controls EasyIO Neo Series EC and CW Controller versions are affected by CVE-2026-64892 and CVE-2026-64893?; What should operators do if they use EasyIO Neo Series EC Controllers V3.3b62 or V3.3b63, or CW Controllers V3.3b24 or V3.3b25?; How do CVE-2026-64892 and CVE-2026-64893 differ for EasyIO Neo Series controllers?; What sensitive information risks are described in the CISA advisories for EasyIO Neo Series controllers?
- How do I check whether my Siemens Industrial Edge Management deployment is in one of the affected version ranges?; What should administrators do after CISA advisory ICSA-26-265-06 for CVE-2026-18963?; What changed in the Siemens update for the reset-credentials vulnerability?; What is the timeline for the Siemens Industrial Edge Management CISA advisory and fix?
- Why do the provided sources for 2027 Men’s College World Series point to CISA advisories instead of sports coverage?; Which Johnson Controls EasyIO controller versions are named in the October 1, 2026 CISA advisories?

Leave a Reply