← Back to Feed
Johnson Controls OpenBlue Employee
CVE-2026-21662CVE-2026-34495CVE-2026-34497
July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL
This CISA advisory highlights multiple vulnerabilities in Johnson Controls OpenBlue Employee (FMS Employee) software. The flaws include unrestricted file upload, stored cross-site scripting, and HTML injection, which could allow an attacker to upload malicious files or execute script-based attacks. Johnson Controls has released an update and recommends defensive measures such as restricting access and enabling security settings.
Key Takeaways
- Multiple vulnerabilities in Johnson Controls OpenBlue Employee allow file upload, XSS, and HTML injection.
- Exploitation could lead to malicious file execution or stored cross-site scripting attacks.
- Johnson Controls recommends applying the latest update and limiting application access to authorized users.