The news
On October 1, the US Cybersecurity and Infrastructure Security Agency (CISA) published industrial control system advisories covering four products that run buildings and vehicles rather than offices: Monta's electric-vehicle charging platform, Armatura One physical access control, the Meari IoT Cloud Platform and Johnson Controls (JCI) EasyIO Neo building controllers. CISA said it had no reports of public exploitation targeting any of them.
The most severe Monta issue, CVE-2026-95102, is a missing-authentication flaw rated 9.4 out of 10 on the CVSS severity scale. Three more Monta flaws, rated 7.5, 7.3 and 6.5, involve no limit on login attempts, predictable session identifiers that let attackers pose as other users, and charger login identifiers that are publicly visible on web mapping platforms. CISA said exploitation could give attackers administrative control of vulnerable charging stations or let them disrupt charging. The advisory covers all versions, and mitigations include enabling an authenticated, encrypted security profile in OCPP, the protocol chargers use to talk to their back end.
Armatura One, from US-based Armatura LLC, is a system that controls physical doors and entry. CISA listed five flaws. The worst, CVE-2023-46604, rated 9.8, is a known deserialization bug in the Apache ActiveMQ message broker embedded in the product, which CISA said can allow remote code execution before any login check. CISA noted that this ActiveMQ flaw is in its Known Exploited Vulnerabilities catalog because of ransomware campaigns, though it said it was not aware of attacks targeting Armatura One specifically. Other issues include a hard-coded encryption key, a vendor-defined default database superuser password and credentials written in plain text to logs. CISA advised upgrading to version 4.7.2, or 4.6.1 for the US edition.
The Meari advisory covers the company's IoT Cloud Platform OpenAPI service, which connects consumer and commercial devices such as cameras to the cloud. Two missing-authorization flaws could let a signed-in user change settings on devices they do not own, or read device data that CISA said exposes credentials, owner details and network data. CISA said Meari, which is based in China, did not respond to its coordination attempts and that no fix is planned.
The Johnson Controls flaw is less serious. CVE-2026-64892, rated 3.5 under CVSS v3.1 and 4.8 under v4.0, could expose sensitive information useful for later attacks on certain EasyIO Neo EC and CW controllers. Johnson Controls has released firmware V3.3b64 and V3.3b26 to fix it.
The numbers
- Highest score (Armatura One, ActiveMQ flaw)
- 9.8
- Monta missing-authentication flaw
- 9.4
- Vulnerabilities across the four advisories
- 12
- Meari fix status
- No fix planned
Why CEOs should care
For CISOs, these products often sit outside the security team's inventory. Charging stations are bought by fleet or real estate teams, door systems by facilities, cameras by whoever needed them. Ask for a list of every cloud-managed building device, who owns it, and whether it can reach the corporate network. Armatura customers should confirm they are on 4.7.2 or 4.6.1, because the embedded ActiveMQ flaw is one ransomware groups have already used elsewhere.
For procurement leaders, the Meari case is the warning. A vendor that does not answer a US government agency is unlikely to answer you during an incident. Add facilities and IoT suppliers to the same vendor-risk questionnaire used for software: a vulnerability disclosure policy, patch timelines, and whether credentials or encryption keys are hard-coded.
For boards and CFOs, these systems control physical outcomes: whether doors open, whether vehicles charge, how buildings run. Ask management who is accountable for operational technology risk and whether insurance and incident response plans cover it.
The bigger picture
CISA's own mitigations for all four advisories repeat the same basics: keep control systems off the open internet, put them behind firewalls separate from business networks and use VPNs for remote access. Those steps are harder to follow when the product is cloud-managed by design, as Monta's and Meari's platforms are, which is why vendor security practices matter as much as network design.
What’s next
Monta and Johnson Controls customers should apply the configuration changes and firmware updates CISA listed, and Armatura customers should upgrade. Meari device owners have no patch to wait for, so the decision is whether to isolate or replace those devices.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







