← Back to Feed

Johnson Controls XAAP Android

July 23, 2026 · CISA (US-CERT) · Severity: CRITICAL

CISA issued a critical advisory on vulnerabilities in the Johnson Controls XAAP Android application used for building management. These flaws could enable remote compromise of access control and environmental systems. Users should immediately update the application and secure management devices.

Key Takeaways

  • CISA critical advisory warns of vulnerabilities in Johnson Controls XAAP Android application for building management.
  • Successful exploitation could allow attackers to remotely compromise building access and environmental control systems.
  • Organizations should update the XAAP Android app and ensure mobile devices used for building management are secured.
☕ Buy a Coffee