← Back to Feed

Johnson Controls OpenBlue Employee

CVE-2026-21662CVE-2026-34495CVE-2026-34497

July 30, 2026 · CISA (US-CERT) · Severity: HIGH

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc.

Key Takeaways

  • Johnson Controls OpenBlue Employee — HIGH severity involving CVE-2026-21662, CVE-2026-34495, CVE-2026-34497
  • CISA advisory provides indicators of compromise and mitigation guidance
  • Organizations should review and apply recommended mitigations promptly
☕ Buy a Coffee