Cryptographic Key Vulnerability in Johnson Controls Airwall
CVE-2026-64887

7HIGH

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-64887?

The use of hard-coded cryptographic keys in Johnson Controls Airwall creates a potential risk of a cryptanalytic attack. This vulnerability affects versions prior to 4.1, leaving systems vulnerable to unauthorized access and data exposure. Organizations utilizing these versions should take immediate steps to update their software and ensure stronger encryption practices are implemented.

Affected Version(s)

Airwall 0 < 4.1

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.