{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-34492/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Airwall"],"_cs_severities":["high"],"_cs_tags":["ics","cve-2026-64887","cve-2026-34492"],"_cs_type":"advisory","_cs_vendors":["Johnson Controls"],"content_html":"\u003cp\u003eJohnson Controls has disclosed two vulnerabilities affecting Airwall products up to and including version 4.0.4. The first, CVE-2026-64887, involves the use of hard-coded cryptographic keys within the application, which are consistent across all installations. This allows an attacker who obtains the key through code analysis or binary inspection to decrypt sensitive application data, configuration files, and database content. The second issue, CVE-2026-34492, is an arbitrary file read vulnerability caused by improper validation of user-supplied input in file system operations. Attackers can leverage path traversal sequences (e.g., ../ or encoded variations) to read sensitive files from the underlying server, including private keys and credential stores. These vulnerabilities pose a significant risk to critical infrastructure sectors, including manufacturing, energy, and transportation, as they could lead to full system compromise if exploited in tandem.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to gain unauthorized access to sensitive system information. By extracting private keys and credentials, an attacker could escalate privileges or pivot into internal networks. Given the deployment of these devices in critical infrastructure sectors, the compromise of Airwall appliances could result in significant operational disruption and data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Johnson Controls Airwall to version 4.1.0 or later immediately to patch both CVE-2026-64887 and CVE-2026-34492.\u003c/li\u003e\n\u003cli\u003eAudit existing deployments for unauthorized access to configuration files and sensitive key stores.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation and strictly restrict management access to these devices, ensuring they are not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eConsult the Johnson Controls Product Security Advisory JCI-PSA-2026-25 and JCI-PSA-2026-18 for detailed hardening steps and remediation guidance.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:52:07Z","date_published":"2026-08-13T16:52:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-airwall/","summary":"Johnson Controls Airwall versions 4.0.4 and earlier are affected by CVE-2026-64887 and CVE-2026-34492, allowing attackers to potentially decrypt sensitive data or perform arbitrary file reads.","title":"Johnson Controls Airwall Hard-coded Credentials and Path Traversal Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-airwall/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-34492","version":"https://jsonfeed.org/version/1.1"}