← Back to Feed
Johnson Controls XAAP Android
CVE-2026-34490
July 23, 2026 · CISA (US-CERT) · Severity: CRITICAL
CISA issued a critical advisory on vulnerabilities in the Johnson Controls XAAP Android application used for building management. These flaws could enable remote compromise of access control and environmental systems. Users should immediately update the application and secure management devices.
Key Takeaways
- View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential. View CVE Details Affected Products Johnson Controls XAAP Android Vendor:Johnson Controls Product Version:Johnson.
- The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment.