CVE-2026-64896: Johnson Controls t2000
Medium severity, CVSS 5.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
Affected products
- Johnson Controls t2000: before 31.6 (fixed in 31.6)
Published 2026-08-27. Last modified 2026-09-03.