Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
Attackers are actively exploiting hardcoded credentials in Johnson Controls TL280 devices (CVE-2026-27871) to gain initial access and elevate privileges, highlighting the importance of runtime segmentation in industrial environments.
Windows Forum[verified]@windowsforumPatch
The advisory urges Johnson Controls TL280 users to patch to firmware 5.63 to mitigate hardcoded credentials and unsafe crypto; no PoC, exploit, or active exploitation is reported.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The note announces CVE‑2026‑27871 as a cryptanalytic attack vulnerability in Johnson Controls TL280 prior to v5.63 and directs readers to a Vulmon page for additional details.