# Johnson Controls Airwall Hit with Hard-coded Key Flaw That Exposes Every Deployment Simultaneously


## The Threat


Johnson Controls' Airwall platform — an industrial network access solution deployed across energy grids, government facilities, transportation networks, and critical manufacturing — contains a hard-coded cryptographic key shared across every installation worldwide. That single architectural failure means the moment one attacker recovers the key from any copy of the application binary, every Airwall deployment on the planet is exposed. There is no per-customer key, no per-device key — just one universal secret baked into the software itself.


This is the worst-case scenario for a cryptographic vulnerability. The key's presence in application code or compiled binaries means it can be extracted through reverse engineering, leaked via decompiled source, or simply published on a forum. Once that happens — and with OT/ICS products, it typically does — attackers can decrypt sensitive configuration data and database files across the entire installed base without needing credentials, network position, or any other precondition beyond knowing the key exists.


A second flaw compounds the problem: CVE-2026-34492 introduces an external control of file name or path vulnerability, giving attackers a path to read arbitrary files on the system. In combination, these two CVEs paint an ugly picture — decrypt the configuration layer to harvest credentials or keys, then leverage the path traversal to access protected files that should never be reachable from outside. Critical infrastructure operators running unpatched Airwall should treat this as an active risk requiring immediate action, not a scheduled maintenance item.


## Severity and Impact


| CVE | CVSS Score | Severity | Vector String | Attack Complexity | CWE |

|-----|------------|----------|---------------|-------------------|-----|

| CVE-2026-64887 | 6.8 | Medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N | High | CWE-321 (Use of Hard-coded Cryptographic Key) |

| CVE-2026-34492 | 6.8 | Medium | CVSS:3.1 | High | CWE-73 (External Control of File Name or Path) |


CVSS scores reflect vendor assessment. The Medium severity rating is technically defensible given the attack complexity, but understates operational risk for critical infrastructure deployments where the breadth of exposure — all installations, all customers, simultaneously — is the primary threat multiplier.


## Affected Products


Johnson Controls Inc. Airwall

  • All versions up to and including 4.0.4

  • Affected sectors per ICS-CERT:

  • Critical Manufacturing
  • Commercial Facilities
  • Government Services and Facilities
  • Transportation Systems
  • Energy

  • Deployment scope: Worldwide


    ## Mitigations


    Patch first. Johnson Controls has released version 4.1.0 as the remediation for both CVEs. All Airwall instances should be updated immediately.


    For organizations that cannot patch immediately, Johnson Controls and ICS-CERT recommend the following interim controls:


    For CVE-2026-64887 (Hard-coded Key):

  • Migrate cryptographic key storage to a hardware security module (HSM) or dedicated key management system (KMS) — the embedded key cannot be rotated without a software update, but isolating affected systems limits the blast radius
  • Apply network segmentation to restrict access to Airwall management interfaces and configuration files
  • Implement monitoring and anomaly detection on key access and retrieval events
  • Audit CI/CD pipelines with secrets-scanning tools to verify the flaw hasn't propagated to internal tooling
  • Follow Johnson Controls' universal hardening guide at [johnsoncontrols.com/trust-center/cybersecurity/resources](https://www.johnsoncontrols.com/trust-center/cybersecurity/resources)

  • For CVE-2026-34492 (Path Traversal):

  • Apply strict access controls and principle of least privilege to all file system paths accessible by Airwall processes
  • Monitor file access logs for unexpected path patterns indicating active exploitation

  • Longer-term:

  • Establish a regular key rotation policy so that future key compromises have bounded exposure windows
  • Move toward per-device or per-deployment unique cryptographic keys as a design standard for any OT/ICS product in your environment

  • Full vendor advisory: [JCI-PSA-2026-25](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories)


    ## References


  • [Johnson Controls Product Security Advisories](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories)
  • [Johnson Controls Cybersecurity Resources & Hardening Guides](https://www.johnsoncontrols.com/trust-center/cybersecurity/resources)
  • [ICS-CERT Advisory — Johnson Controls Airwall](https://www.cisa.gov/news-events/ics-advisories)
  • [NIST NVD — CVE-2026-64887](https://nvd.nist.gov/vuln/detail/CVE-2026-64887)
  • [NIST NVD — CVE-2026-34492](https://nvd.nist.gov/vuln/detail/CVE-2026-34492)

  • ---


    ## HackWire Analysis


    The 6.8 CVSS score on CVE-2026-64887 is misleading in a way that matters. "Medium" implies a contained, qualified risk. What it actually describes is a single cryptographic secret that unlocks the entire global installed base — simultaneously, universally, without differentiation. The CVSS attack complexity is rated "High" because actually extracting a hard-coded key from a binary requires some skill. But that's a one-time effort by one attacker. Once extracted and published — and ICS/OT vulnerabilities have a well-documented history of ending up on Pastebin or in private exploit kits — the complexity drops to zero for every subsequent actor. The "High" complexity multiplier is a one-time friction tax, not a lasting protection.


    This vulnerability class is not new, but its persistence in industrial control systems is remarkable. Hard-coded credentials and keys were flagged as a critical problem in ICS software over a decade ago. CISA has published guidance repeatedly. Yet here we are in 2026 with a vendor shipping an OT network access platform — something explicitly designed to control access to critical infrastructure — with a universal key embedded in the binary.


    What makes Airwall particularly sensitive is its function. This isn't a general-purpose enterprise application; it's an industrial network access control product. The sectors listed in this advisory — energy, transportation, government facilities, critical manufacturing — are precisely the environments where network access control failure has physical-world consequences. Defenders in these environments should not wait for routine patch cycles. The combination of the hardcoded key and the path traversal flaw creates a reliable exploitation chain, and threat actors targeting OT infrastructure are both motivated and technically capable of chaining exactly this kind of pair.


    If you operate Airwall at 4.0.4 or below, patch to 4.1.0 now. If patching requires a maintenance window, segment the management interfaces immediately and assume the key has already been extracted somewhere.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)