← Back to Feed

Johnson Controls OpenBlue Employee

CVE-2026-21662CVE-2026-34495CVE-2026-34497

July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL

This CISA advisory highlights multiple vulnerabilities in Johnson Controls OpenBlue Employee (FMS Employee) software. The flaws include unrestricted file upload, stored cross-site scripting, and HTML injection, which could allow an attacker to upload malicious files or execute script-based attacks. Johnson Controls has released an update and recommends defensive measures such as restricting access and enabling security settings.

Key Takeaways

  • Multiple vulnerabilities in Johnson Controls OpenBlue Employee allow file upload, XSS, and HTML injection.
  • Exploitation could lead to malicious file execution or stored cross-site scripting attacks.
  • Johnson Controls recommends applying the latest update and limiting application access to authorized users.
☕ Buy a Coffee