CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Johnson Controls OpenBlue Employee

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3574

As cited

Copy frozen at (site build).

vulnerabilities

Johnson Controls OpenBlue Employee

Johnson Controls has disclosed three vulnerabilities in OpenBlue Employee (FMS Employee) version 2025.3.1 and earlier that could allow attackers to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The vulnerabilities affect critical infrastructure sectors worldwide, including manufacturing, energy, transportation, and government facilities. Johnson Controls recommends applying the latest product update and implementing additional controls such as authentication enforcement, web application firewalls, and network access restrictions.

Why it matters: Operators of Johnson Controls OpenBlue Employee in critical infrastructure must patch to the latest version immediately, as successful exploitation could compromise facility management systems used across manufacturing, energy, transportation, and government sectors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Johnson Controls OpenBlue Employee

Johnson Controls OpenBlue Employee versions through V2025.3.1 contain three vulnerabilities: unrestricted file uploads (CVE-2026-21662), stored cross-site scripting (CVE-2026-34495), and improper HTML neutralization (CVE-2026-34497). These flaws could allow attackers to upload malicious files, execute persistent XSS attacks, or inject arbitrary content. The vendor advises applying the latest product update and implementing mitigations including access restrictions, web application firewall deployment, and periodic file review.

Why it matters: Organizations operating OpenBlue Employee across critical infrastructure, manufacturing, and government sectors must patch to the latest version immediately to prevent file upload exploitation and stored XSS attacks that could compromise employee data and system integrity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Johnson Controls OpenBlue Employee

Johnson Controls OpenBlue Employee versions through V2025.3.1 contain three vulnerabilities: unrestricted file uploads (CVE-2026-21662), stored cross-site scripting (CVE-2026-34495), and improper HTML neutralization (CVE-2026-34497). These flaws could allow attackers to upload malicious files, execute persistent XSS attacks, or inject arbitrary content. The vendor advises applying the latest product update and implementing mitigations including access restrictions, web application firewall deployment, and periodic file review.

Why it matters: Organizations operating OpenBlue Employee across critical infrastructure, manufacturing, and government sectors must patch to the latest version immediately to prevent file upload exploitation and stored XSS attacks that could compromise employee data and system integrity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary