CVE-2026-71449: Johnson Controls Easyio FS32

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.

Affected products

Published 2026-10-01. Last modified 2026-10-02.