<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the CISA CNA root</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Latest vulnerabilities published by the CNAs operating under the CISA root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:11 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-27873 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-27873</link>
      <description>- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.

This issue affects EasyIO FG: before 2.0b52.</description>
      <content:encoded>- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.

This issue affects EasyIO FG: before 2.0b52.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-27873</guid>
      <pubDate>Thu, 01 Oct 2026 21:27:33 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-64893 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-64893</link>
      <description>- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.

This issue affects EasyIO NEO: before 3.3b25.</description>
      <content:encoded>- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.

This issue affects EasyIO NEO: before 3.3b25.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-64893</guid>
      <pubDate>Thu, 01 Oct 2026 21:25:26 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-64892 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-64892</link>
      <description>- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.

This issue affects Easy IO Neo: before 3.3b63.</description>
      <content:encoded>- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.

This issue affects Easy IO Neo: before 3.3b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-64892</guid>
      <pubDate>Thu, 01 Oct 2026 21:23:33 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-34494 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-34494</link>
      <description>- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.

This issue affects Neo Series MVP2: before 3.3b63.</description>
      <content:encoded>- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.

This issue affects Neo Series MVP2: before 3.3b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-34494</guid>
      <pubDate>Thu, 01 Oct 2026 21:20:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-34493 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-34493</link>
      <description>- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.

This issue affects EasyIO FS32: before 3.3b63.</description>
      <content:encoded>- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.

This issue affects EasyIO FS32: before 3.3b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-34493</guid>
      <pubDate>Thu, 01 Oct 2026 21:18:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71449 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-71449</link>
      <description>: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.

This issue affects EasyIO FS32: before 3.0b63.</description>
      <content:encoded>: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.

This issue affects EasyIO FS32: before 3.0b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-71449</guid>
      <pubDate>Thu, 01 Oct 2026 21:16:57 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71448 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-71448</link>
      <description>: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.

This issue affects EasyIO FS32: before 3.0b63.</description>
      <content:encoded>: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.

This issue affects EasyIO FS32: before 3.0b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-71448</guid>
      <pubDate>Thu, 01 Oct 2026 21:15:22 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71454 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-71454</link>
      <description>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).

This issue affects CAPEC-63: before 3.0b63.</description>
      <content:encoded>Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS).

This issue affects CAPEC-63: before 3.0b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-71454</guid>
      <pubDate>Thu, 01 Oct 2026 21:13:17 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71453 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-71453</link>
      <description>- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.

This issue affects EasyIO FS32: before 3.0b63.</description>
      <content:encoded>- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.

This issue affects EasyIO FS32: before 3.0b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-71453</guid>
      <pubDate>Thu, 01 Oct 2026 21:10:08 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-71452 (jci)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-71452</link>
      <description>- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.

This issue affects EasyIO FS32: before 3.0b63.</description>
      <content:encoded>- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.

This issue affects EasyIO FS32: before 3.0b63.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-71452</guid>
      <pubDate>Thu, 01 Oct 2026 21:06:20 +0000</pubDate>
    </item>
  </channel>
</rss>
