As cited
Copy frozen at (site build).
vulnerabilities
Johnson Controls OpenBlue Employee
Johnson Controls has disclosed three vulnerabilities in OpenBlue Employee (FMS Employee) version 2025.3.1 and earlier that could allow attackers to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The vulnerabilities affect critical infrastructure sectors worldwide, including manufacturing, energy, transportation, and government facilities. Johnson Controls recommends applying the latest product update and implementing additional controls such as authentication enforcement, web application firewalls, and network access restrictions.
Why it matters: Operators of Johnson Controls OpenBlue Employee in critical infrastructure must patch to the latest version immediately, as successful exploitation could compromise facility management systems used across manufacturing, energy, transportation, and government sectors.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Johnson Controls OpenBlue Employee
Johnson Controls OpenBlue Employee versions through V2025.3.1 contain three vulnerabilities: unrestricted file uploads (CVE-2026-21662), stored cross-site scripting (CVE-2026-34495), and improper HTML neutralization (CVE-2026-34497). These flaws could allow attackers to upload malicious files, execute persistent XSS attacks, or inject arbitrary content. The vendor advises applying the latest product update and implementing mitigations including access restrictions, web application firewall deployment, and periodic file review.
Why it matters: Organizations operating OpenBlue Employee across critical infrastructure, manufacturing, and government sectors must patch to the latest version immediately to prevent file upload exploitation and stored XSS attacks that could compromise employee data and system integrity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Johnson Controls OpenBlue Employee
Johnson Controls OpenBlue Employee versions through V2025.3.1 contain three vulnerabilities: unrestricted file uploads (CVE-2026-21662), stored cross-site scripting (CVE-2026-34495), and improper HTML neutralization (CVE-2026-34497). These flaws could allow attackers to upload malicious files, execute persistent XSS attacks, or inject arbitrary content. The vendor advises applying the latest product update and implementing mitigations including access restrictions, web application firewall deployment, and periodic file review.
Why it matters: Organizations operating OpenBlue Employee across critical infrastructure, manufacturing, and government sectors must patch to the latest version immediately to prevent file upload exploitation and stored XSS attacks that could compromise employee data and system integrity.
- Source published
- First seen by Cybersecurity Tracker