← Back to Feed

Johnson Controls OpenBlue Employee

CVE-2026-21662CVE-2026-34495CVE-2026-34497

July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

Key Takeaways

  • View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious.
  • The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee). OpenBlue Employee (FMS Employee): <=V2025.3.1 Product Status:known_affected Remediations MitigationJohnson.
☕ Buy a Coffee