Government Advisory

Security Flaw Found in Johnson Controls TL280 Devices

CISA · 6 Aug 2026
Key Takeaway If your business uses Johnson Controls TL280 devices, check your firmware version and update to 5.63 or later to close this security gap.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory about a vulnerability affecting Johnson Controls Inc. TL280 devices running versions earlier than 5.63. The issue stems from the use of a weak or outdated cryptographic algorithm, which could allow an attacker to access sensitive information stored on or transmitted by the device.

The vulnerability, tracked as CVE-2026-27871, has been rated with a CVSS v3 score of 4.1, indicating a low-to-moderate severity. Johnson Controls devices are used globally across several critical infrastructure sectors, including manufacturing, commercial facilities, government services, transportation, and energy—meaning businesses in these industries should pay particular attention to whether they use affected equipment.

While the severity rating is relatively low, weak cryptography can still expose confidential data to interception or decryption by determined attackers, especially in networked environments. Organisations using TL280 devices should check their current firmware version and plan an update if they are running a version prior to 5.63.

Johnson Controls ICS Security CISA Advisory Cryptography Critical Infrastructure

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.