Vulnerability record

CVE-2026-27873

Severity: ElevatedExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-27873 scored CVSS 5.6

    Basis: NIST National Vulnerability Database

  2. Disclosed

    Johnson Controls EasyIO FG

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

References