VORANT. Threat Intelligence Research Sign in Create a free account

Johnson Controls EasyIO FG flaws enable full device takeover

routine vulnerability manufacturinggovernment-nationaltransportationenergy

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Two unpatched vulnerabilities in Johnson Controls EasyIO FG firmware (<=2.0b52) could let an attacker gain full unauthorized device access; no active exploitation reported.

CISA published an ICS advisory covering two vulnerabilities (CVE-2026-27872 and CVE-2026-27873) affecting Johnson Controls EasyIO FG building automation controllers running firmware version 2.0b52 or earlier. Successful exploitation could grant an attacker full unauthorized access to the affected device. The advisory notes that these flaws carry high attack complexity and are not exploitable remotely, reducing the likelihood of opportunistic mass exploitation, though local or adjacent-network attackers could still leverage them.

The vulnerabilities were responsibly disclosed to Johnson Controls by researchers Gabriele Gardois, Zachary Bushell, and Lorenzo De Carli of the University of Calgary. CISA states no known public exploitation targeting these issues has been reported at this time. EasyIO FG devices are deployed worldwide across critical manufacturing, commercial facilities, government services, transportation systems, and energy sectors, making the installed base broad even if individual exploitation requires proximity or complex conditions.

Defenders operating EasyIO FG controllers should inventory affected firmware versions, apply vendor patches or mitigations when available, and follow standard ICS network-segmentation guidance: isolate control-system networks from business networks and the internet, restrict remote access to secured VPNs, and monitor for anomalous local or network access attempts against these devices.

Mentioned in this report

Vulnerabilities CVE-2026-27872CVE-2026-27873

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,850 reports from 149 sources, 467 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs