Johnson Controls vulnerabilities
9 CVEs tracked
This reporting period reveals critical vulnerabilities across multiple Johnson Controls products. Key issues include an SSRF flaw in CCure 9000/Victor Application Server (CVE-2026-21653), file upload and XSS vulnerabilities in FM Systems Employee (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497), and hard-coded cryptographic keys with file manipulation flaws in Airwall (CVE-2026-64887, CVE-2026-34492). Defenders should prioritize patching for privilege escalation (CVE-2026-34496) in perimeter systems like Victor Web and the Airwall, and ensure immediate updates to prevent cryptanalytic attacks and data exposure.
Azərbaycanca: Hesabat dövründə Johnson Controls məhsullarında müxtəlif kritik zəifliklər aşkarlanıb. Əsas diqqət çəkən məsələlər CCure 9000/Victor Application Server-də SSRF (CVE-2026-21653), FM Systems Employee platformasında fayl yükləmə və XSS (CVE-2026-21662, CVE-2026-34495, CVE-2026-34497) zəiflikləri, eləcə də Airwall-da sərt kodlaşdırılmış kriptoqrafik açar və fayl manipulyasiyası (CVE-2026-64887, CVE-2026-34492) problemləridir. Müdafiəçilər xüsusilə Victor Web (CVE-2026-34496) və Airwall kimi perimetr sistemlərində imtiyaz artırma və fayl manipulyasiyası hücumlarına qarşı təcili yeniləmələrə diqqət yetirməlidir.
This vendor's CVEs9
This hub is built from skopnix's own reporting on Johnson Controls: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.