Johnson Controls OpenBlue Employee flaws patched
CISA warns of three vulnerabilities in Johnson Controls OpenBlue Employee that could let attackers upload malicious files or inject scripts, with no known active exploitation.
CISA published an ICS advisory detailing three vulnerabilities in Johnson Controls' OpenBlue Employee (FMS Employee) application, versions V2025.3.1 and earlier. The flaws include an unrestricted file upload weakness (CVE-2026-21662), a stored cross-site scripting issue (CVE-2026-34495), and an HTML injection vulnerability (CVE-2026-34497). Successful exploitation could allow an attacker to upload malicious files, execute persistent XSS payloads against other users, or manipulate page content via injected HTML.
OpenBlue is deployed worldwide across critical manufacturing, commercial facilities, government services, transportation, and energy sectors, making the application's exposure notable even though CISA states no known public exploitation has been reported. Johnson Controls reported the issues to CISA and has released updates; the vendor recommends patching, restricting application access, enabling file-location visibility controls, deploying WAFs, and limiting internet exposure. This is a standard vendor-disclosed vulnerability advisory rather than an active-exploitation event.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free