← Back to Feed
Johnson Controls OpenBlue Employee
CVE-2026-21662CVE-2026-34495CVE-2026-34497
July 30, 2026 · CISA (US-CERT) · Severity: HIGH
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) <=V2025.3.1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities v3 2.4 Johnson Controls Inc.
Key Takeaways
- Johnson Controls OpenBlue Employee — HIGH severity involving CVE-2026-21662, CVE-2026-34495, CVE-2026-34497
- CISA advisory provides indicators of compromise and mitigation guidance
- Organizations should review and apply recommended mitigations promptly