CVE-2026-64896
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
- Published Aug 27, 2026
- CVSS 5.2 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available