Vulnerabilities & PatchesEmerging1 src
Johnson Controls OpenBlue Employee
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) =V2025. 3. 1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities
v3 2. 4 Johnson Controls Inc.
CVE-2026-21662CVE-2026-34495CVE-2026-34497