logo

Johnson Controls OpenBlue Employee

ID: c7eb423c-ce5f-5e81-8208-bf369060c7f8

STIX ID: report--c7eb423c-ce5f-5e81-8208-bf369060c7f8

Feed Name: CISA Advisories

Threat Score
20/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: CISA

...
...

CISA published an advisory for Johnson Controls OpenBlue Employee (<=V2025.3.1) describing multiple web application vulnerabilities — unrestricted file upload (CWE-434), stored XSS (CWE-79), and HTML/script-related injection (CWE-80) — that could allow attackers to upload malicious files or inject persistent malicious content; the report lists affected sectors worldwide, provides mitigation guidance, and states no known public exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.