← Back to home
ICSA-26-211-02  ·  Published 2026-07-30  ·  View on CISA ICS-CERT ↗

Johnson Controls OpenBlue Employee

CVSS 2.4 LOW

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.

Remediations

  • Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.
  • Limit application access to authorized users and enforce strong authentication.
  • Enable the "Do Not Show Files" location setting if the feature is not being actively used.
  • Employ a Web Application Firewall (WAF) to help detect and block malicious requests.
  • Investigate and promptly remove any suspicious files or content discovered within the application.
  • Limit internet exposure by restricting access to trusted networks or VPN users where practical.
  • Review uploaded content periodically and remove content that is no longer required.
  • For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-09 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories

Affected Vendors

Johnson Controls Inc.

Affected Products (1)

Johnson Controls Inc. · OpenBlue Employee (FMS Employee) <=V2025.3.1

Affected Sectors

Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more