# Johnson Controls OpenBlue Employee flaws patched

Published: 2026-07-30 · Severity: medium · Sectors: manufacturing, government-national, transportation, energy
Canonical: https://vorant.io/reports/834dafd3-2b14-5ef4-9883-3a4bac2ea840/johnson-controls-openblue-employee-flaws-patched

> CISA warns of three vulnerabilities in Johnson Controls OpenBlue Employee that could let attackers upload malicious files or inject scripts, with no known active exploitation.

CISA published an ICS advisory detailing three vulnerabilities in Johnson Controls' OpenBlue Employee (FMS Employee) application, versions V2025.3.1 and earlier. The flaws include an unrestricted file upload weakness (CVE-2026-21662), a stored cross-site scripting issue (CVE-2026-34495), and an HTML injection vulnerability (CVE-2026-34497). Successful exploitation could allow an attacker to upload malicious files, execute persistent XSS payloads against other users, or manipulate page content via injected HTML.

OpenBlue is deployed worldwide across critical manufacturing, commercial facilities, government services, transportation, and energy sectors, making the application's exposure notable even though CISA states no known public exploitation has been reported. Johnson Controls reported the issues to CISA and has released updates; the vendor recommends patching, restricting application access, enabling file-location visibility controls, deploying WAFs, and limiting internet exposure. This is a standard vendor-disclosed vulnerability advisory rather than an active-exploitation event.

## Mentioned in this report

- Vulnerabilities: CVE-2026-21662, CVE-2026-34495, CVE-2026-34497

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/834dafd3-2b14-5ef4-9883-3a4bac2ea840/johnson-controls-openblue-employee-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
