# Johnson Controls EasyIO FG flaws enable full device takeover

Published: 2026-10-06 · Severity: routine · Sectors: manufacturing, government-national, transportation, energy
Canonical: https://vorant.io/reports/05d380a8-2bee-51c7-baa8-d8ff4915920a/johnson-controls-easyio-fg-flaws-enable-full-device-takeover

> Two unpatched vulnerabilities in Johnson Controls EasyIO FG firmware (<=2.0b52) could let an attacker gain full unauthorized device access; no active exploitation reported.

CISA published an ICS advisory covering two vulnerabilities (CVE-2026-27872 and CVE-2026-27873) affecting Johnson Controls EasyIO FG building automation controllers running firmware version 2.0b52 or earlier. Successful exploitation could grant an attacker full unauthorized access to the affected device. The advisory notes that these flaws carry high attack complexity and are not exploitable remotely, reducing the likelihood of opportunistic mass exploitation, though local or adjacent-network attackers could still leverage them.

The vulnerabilities were responsibly disclosed to Johnson Controls by researchers Gabriele Gardois, Zachary Bushell, and Lorenzo De Carli of the University of Calgary. CISA states no known public exploitation targeting these issues has been reported at this time. EasyIO FG devices are deployed worldwide across critical manufacturing, commercial facilities, government services, transportation systems, and energy sectors, making the installed base broad even if individual exploitation requires proximity or complex conditions.

Defenders operating EasyIO FG controllers should inventory affected firmware versions, apply vendor patches or mitigations when available, and follow standard ICS network-segmentation guidance: isolate control-system networks from business networks and the internet, restrict remote access to secured VPNs, and monitor for anomalous local or network access attempts against these devices.

## Mentioned in this report

- Vulnerabilities: CVE-2026-27872, CVE-2026-27873

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/05d380a8-2bee-51c7-baa8-d8ff4915920a/johnson-controls-easyio-fg-flaws-enable-full-device-takeover.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
