Critical Security Flaws Identified in Johnson Controls Airwall Devices
Two critical vulnerabilities, CVE-2026-34492 and CVE-2026-64887, have been found in Johnson Controls Airwall devices preceding version 4.1. These flaws include an external control of file name/path allowing file manipulation and a hard-coded cryptographic key enabling cryptanalytic attacks. Users are strongly advised to update their Airwall systems to version 4.1 or later to mitigate these significant security risks.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.