← Back to Feed
Johnson Controls XAAP Android
July 23, 2026 · CISA (US-CERT) · Severity: CRITICAL
CISA issued a critical advisory on vulnerabilities in the Johnson Controls XAAP Android application used for building management. These flaws could enable remote compromise of access control and environmental systems. Users should immediately update the application and secure management devices.
Key Takeaways
- CISA critical advisory warns of vulnerabilities in Johnson Controls XAAP Android application for building management.
- Successful exploitation could allow attackers to remotely compromise building access and environmental control systems.
- Organizations should update the XAAP Android app and ensure mobile devices used for building management are secured.