← Back to Feed

Johnson Controls XAAP Android

CVE-2026-34490

July 23, 2026 · CISA (US-CERT) · Severity: CRITICAL

CISA issued a critical advisory on vulnerabilities in the Johnson Controls XAAP Android application used for building management. These flaws could enable remote compromise of access control and environmental systems. Users should immediately update the application and secure management devices.

Key Takeaways

  • View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential. View CVE Details Affected Products Johnson Controls XAAP Android Vendor:Johnson Controls Product Version:Johnson.
  • The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment.
☕ Buy a Coffee