If you are building an AI system that connects to industrial equipment, control systems or critical infrastructure, audit every component in the chain this week - not just your AI code. Basic security flaws like hardcoded keys can expose the entire system, even if your logic is secure. This is especially true if you work with clients in energy, transport or manufacturing.
CISA published a security advisory on 13 August 2026 covering two vulnerabilities in Johnson Controls Airwall, affecting versions 4.0.4 and above. The vulnerabilities - CVE-2026-64887 (use of a hardcoded cryptographic key) and CVE-2026-34492 (external control of file name or path) - are rated CVSS v3 6.8 and could allow an attacker to decrypt sensitive information, bypass authentication controls, read arbitrary files or gain access to protected system resources.
What happened
The first vulnerability, CVE-2026-64887, stems from a cryptographic key embedded in the product. This means anyone who knows the key can decrypt encrypted traffic or impersonate a legitimate system. The second vulnerability, CVE-2026-34492, allows an attacker to control file paths the system accesses, potentially exposing configuration files, credentials or other sensitive information.
Airwall is a product designed to secure remote access to industrial control systems (ICS) and operational technology (OT) infrastructure. It is used in sectors such as energy, transport and manufacturing - precisely the places where a security vulnerability can be critical.
Why it matters beyond the headline
Israeli businesses building custom AI systems, especially those connecting to industrial or critical infrastructure, need to understand that their system security depends on every link in the chain. You can build a perfectly secure AI model, but if it connects through network or control equipment with basic flaws like hardcoded keys, the entire system is exposed.
This is especially relevant for companies working with clients in energy, water, transport or manufacturing - sectors where AI systems need to communicate with existing industrial equipment. The problem is that ICS and OT equipment is often installed for many years, and security updates do not always arrive quickly.
What to do this week
If you are building or planning an AI system that connects to industrial equipment, map every component in the chain - not just your servers and code. Check which network, control or security products sit between your AI model and the physical systems. Ask the client or infrastructure team for a list of versions and recent security updates.
If you work with clients in regulated sectors, ensure there is a defined process for updating security components even after the system goes live. Vulnerabilities like these are discovered all the time, and a system that was secure at installation can be vulnerable a month later. For more on building managed automation systems that include ongoing security monitoring.
Frequently asked
Not directly. The vulnerabilities affect Johnson Controls Airwall equipment used to secure remote access to industrial control systems. If your AI system does not connect to such equipment or does not pass through Airwall, there is no direct impact.
Ask the client's infrastructure or security team which security and network products sit between your system and the industrial equipment. Request a list of components and versions, and check if there are pending security updates. This is a standard part of integration in critical systems.
A short call, no commitment, and we will tell you whether it is relevant to your business or not.