Government Advisory

CISA Flags Vulnerabilities in Johnson Controls Airwall Security Devices

CISA · 13 Aug 2026
Key Takeaway Check with your IT provider or vendors whether any Johnson Controls Airwall devices are in use in your environment, and ensure they are updated to a patched version as soon as one is available.

CISA has issued an advisory regarding two vulnerabilities affecting Johnson Controls Inc. Airwall devices running version 4.0.4 and earlier. The flaws include the use of a hard-coded cryptographic key and an issue allowing external control of file names or paths, which together could let an attacker decrypt sensitive data, bypass authentication, read arbitrary files, or access protected system resources without authorization.

The affected product is used across multiple critical infrastructure sectors worldwide, including critical manufacturing, commercial facilities, government services, transportation, and energy. Johnson Controls, headquartered in Ireland, has products deployed globally, meaning organisations using Airwall for secure network segmentation should treat this advisory seriously, even though the vulnerabilities carry a moderate CVSS score of 6.8.

While Australian small businesses may not directly operate Airwall devices, many rely on managed service providers or larger partners who use industrial control and network security products like this. Understanding how vulnerabilities in third-party security tools can cascade through supply chains is an important part of overall cyber risk awareness.

ICS Security Vulnerability Advisory Johnson Controls CISA Critical Infrastructure

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.