← Back to Feed
Johnson Controls OpenBlue Employee
CVE-2026-21662CVE-2026-34495CVE-2026-34497
July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.
Key Takeaways
- View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious.
- The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee). OpenBlue Employee (FMS Employee): <=V2025.3.1 Product Status:known_affected Remediations MitigationJohnson.