CVE-2026-34494: Johnson Controls Neo Series MVP2

High severity, CVSS 7.2. EPSS: 0.2% chance of exploitation in the next 30 days.

- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.

Affected products

Published 2026-10-01. Last modified 2026-10-02.