← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 30, 2026 · 12:00via CISA Alerts

Johnson Controls OpenBlue Employee

Brief

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions of Johnson Controls OpenBlue Employee are affected: OpenBlue Employee (FMS Employee) =V2025.

  • 1 (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) CVSS Vendor Equipment Vulnerabilities

v3 2. 4 Johnson Controls Inc.

Read more on CISA Alerts