Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks
ID: 5b9333b7-e506-566c-8724-a5dd02161055
STIX ID: report--5b9333b7-e506-566c-8724-a5dd02161055
Feed Name: cybersecurityNews.com
A CISA-republished advisory warns of a critical, unauthenticated SQL injection vulnerability (CVE-2025-26385, CVSS 10.0) affecting six Johnson Controls ICS products used across critical infrastructure sectors; exploitation could enable remote attackers to execute arbitrary SQL commands to alter, delete, or exfiltrate sensitive data. The advisory identifies impacted products, recommends immediate mitigations (network isolation, firewalls, patched VPNs, segmentation/air-gapping for legacy systems), and notes no known public exploitation as of January 27, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
