CVE-2026-64887: Airwall - Hardcoded Secrets
Published Aug 14, 2026
·Updated
Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.
This issue affects Airwall: before 4.1.
Affected Software
1 affected component
Johnson Controls Airwall<4.1
Event History
Aug 14, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-64887?
CVE-2026-64887 has a risk score of 55, indicating a medium severity vulnerability.
2
How do I fix CVE-2026-64887?
To fix CVE-2026-64887, ensure you upgrade to Airwall version 4.1 or later where the hard-coded cryptographic keys issue has been addressed.
3
What types of attacks does CVE-2026-64887 allow?
CVE-2026-64887 allows for cryptanalytic attacks due to the use of hard-coded cryptographic keys.
4
Which versions of Airwall are affected by CVE-2026-64887?
CVE-2026-64887 affects all versions of Johnson Controls Airwall before version 4.1.
5
Who is impacted by CVE-2026-64887?
Organizations using Johnson Controls Airwall versions prior to 4.1 are impacted by CVE-2026-64887.