CISA says Airwall versions 4.0.4 and earlier contain flaws that could expose sensitive data or allow unauthorized access. A patch is available.
What to know
- CISA lists Johnson Controls Airwall versions 4.0.4 and earlier as affected.
- The vulnerabilities could allow sensitive data to be decrypted or arbitrary files to be read, according to CISA.
- Johnson Controls recommends applying version 4.1.0 or later patches for all Airwalls.
- CISA says no known public exploitation targeting these vulnerabilities had been reported and that they are not exploitable remotely at this time.
- Organizations using Airwall should review CISA and Johnson Controls guidance before making changes, including network isolation and secure remote-access practices.
What CISA reported
In an advisory released August 13, 2026, CISA described two vulnerabilities in Johnson Controls Inc. Airwall. The affected versions are Airwall 4.0.4 and earlier.
CISA says successful exploitation could let an attacker decrypt sensitive data, bypass authentication controls, read arbitrary files, or gain unauthorized access to protected system resources. Johnson Controls reported the vulnerabilities to CISA.
Why these flaws matter
One vulnerability, CVE-2026-64887, involves a hard-coded password or cryptographic key. CISA says the same key is used across all installations and customer organizations. If an attacker obtains access to the application code or binary files, the key could be used to decrypt sensitive application data in configuration and database files.
The second issue, CVE-2026-34492, is an arbitrary file-read vulnerability. CISA says user-supplied input can be used in filesystem operations without adequate validation, potentially exposing files that the application is allowed to read, including configuration files, source code, credential stores, and private keys.
These issues concern organizations that use or manage Johnson Controls Airwall. They are not a general indication that every home computer, family network, or small-business computer is affected. Users should first determine whether Airwall is present in their environment rather than making changes based on the advisory alone.
What CISA and Johnson Controls recommend
Johnson Controls recommends applying version 4.1.0 or later patches for all Airwalls. Organizations should confirm the correct update process and review the vendor’s product security advisories and hardening guidance before proceeding.
For the hard-coded-key issue, the guidance includes using secure key-management systems or hardware security modules, rotating keys regularly, using unique keys for each device or deployment, removing hard-coded keys from code and binaries, limiting access to keys, and monitoring key use.
For the arbitrary-file-read issue, the guidance includes validating and sanitizing user input, allowing only approved file paths and directories, resolving path-traversal sequences before validation, limiting filesystem permissions, and restricting the application’s filesystem scope.
Additional steps for organizations
CISA recommends minimizing network exposure for control-system devices and systems, keeping them off the public internet, placing them behind firewalls, and isolating them from business networks. When remote access is required, CISA recommends more secure methods such as a VPN, while noting that VPNs and the devices connected to them must also be kept updated.
CISA advises organizations to perform an impact analysis and risk assessment before deploying defensive measures. Administrators who suspect malicious activity should follow their established internal procedures and report findings to CISA for tracking and correlation.
CISA also advises against clicking links or opening attachments in unsolicited email messages. This is a general precaution relevant to employees and home users, especially when attackers may use security news as a pretext for phishing.
What everyday users should do
If you do not use or manage Johnson Controls Airwall, the advisory does not call for a change to your personal computer based on the information provided. If your workplace or small business uses Airwall, contact the responsible administrator or IT provider and ask them to check the deployed version and apply the vendor-recommended patch where appropriate.
Do not download a supposed Airwall update from an unsolicited email or unfamiliar website. Use the CISA advisory and Johnson Controls’ official security resources to locate the relevant guidance, and follow your organization’s normal change-management process.
Does this affect me?
- Who may be affected
- Technicians
- How to check
- Confirm whether you use the named product, service, version, or account described by the primary source.
- What to do
- Follow the vendor or agency guidance that applies to your environment; prioritize confirmed updates and account protections.
- What to avoid
- Do not install unsolicited fixes, call numbers from pop-ups, or assume every device is affected.
Common questions
Does this affect every computer or account?
No. Exposure depends on the affected product, version, configuration, or service described by the primary source.
What is the safest first step?
Verify the product or account involved and use the official source or vendor update path rather than links from unsolicited messages.
Primary source
Source: CISA, “Johnson Controls Inc. Airwall,” ICSA-26-225-03, published August 13, 2026: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03. Readers should consult the linked original for complete technical details. Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Aug 13, 2026 at 5:07 pm EDT. Updates and corrections are noted here when material facts change.
