ICSA-26-211-02
·
Published 2026-07-30
·
View on CISA ICS-CERT ↗
Johnson Controls OpenBlue Employee
CVSS 2.4
LOW
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.
CVEs (3)
Remediations
- Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: Apply the latest product update for OpenBlue Employee (FMS Employee). Customers running V2025.3.1 [LV1.1] or earlier should apply the latest available update.
- Limit application access to authorized users and enforce strong authentication.
- Enable the "Do Not Show Files" location setting if the feature is not being actively used.
- Employ a Web Application Firewall (WAF) to help detect and block malicious requests.
- Investigate and promptly remove any suspicious files or content discovered within the application.
- Limit internet exposure by restricting access to trusted networks or VPN users where practical.
- Review uploaded content periodically and remove content that is no longer required.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-09 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
Affected Vendors
Johnson Controls Inc.
Affected Products (1)
Johnson Controls Inc.
·
OpenBlue Employee (FMS Employee)
<=V2025.3.1
Affected Sectors
Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more