# Johnson Controls Airwall hardcoded key, path traversal flaws

Published: 2026-08-13 · Severity: routine · Sectors: manufacturing, government-national, transportation, energy
Canonical: https://vorant.io/reports/032a1664-dfd8-5637-bd27-ac3647d4da72/johnson-controls-airwall-hardcoded-key-path-traversal-flaws

> Johnson Controls Airwall ≤4.0.4 has a hardcoded cryptographic key and an arbitrary file read flaw that could let attackers decrypt data or read sensitive files.

CISA published an ICS advisory for Johnson Controls Airwall versions 4.0.4 and earlier, detailing two vulnerabilities. CVE-2026-64887 involves a hardcoded cryptographic key embedded identically across all Airwall installations, allowing anyone who discovers the key to decrypt sensitive configuration and database data across every deployment. CVE-2026-34492 is a path traversal/arbitrary file read issue where unsanitized user input passed to filesystem functions could allow attackers to retrieve arbitrary files, including credential stores and private keys.

Airwall is deployed worldwide across critical manufacturing, commercial facilities, government facilities, transportation, and energy sectors. CISA notes no known public exploitation of these flaws and states they are not remotely exploitable and have high attack complexity, reducing near-term urgency. Johnson Controls has released version 4.1.0 to address both issues and recommends standard hardening practices including key management via KMS/HSM, input validation, and network isolation for control system devices.

These are vendor-disclosed vulnerabilities rather than actively exploited threats, with remediation available. Organizations running affected Airwall versions should prioritize patching to 4.1.0 or later and follow Johnson Controls' hardening guidance, particularly around cryptographic key management given the severity of a shared hardcoded key across all customer deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-34492, CVE-2026-64887

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/032a1664-dfd8-5637-bd27-ac3647d4da72/johnson-controls-airwall-hardcoded-key-path-traversal-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
