← Back to home
ICSA-26-204-02  ·  Published 2026-07-23  ·  View on CISA ICS-CERT ↗

Johnson Controls XAAP Android

CVSS 3.3 LOW

Risk Summary

Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.

CVEs (1)

Remediations

  • Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.
  • Johnson Controls recommends users restrict physical access to devices running the XAAP Android application.
  • Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place.
  • Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities.
  • Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect local application data.
  • For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-10.

Affected Vendors

Johnson Controls

Affected Products (1)

Johnson Controls · XAAP Android <1.53

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more