CISA has published an industrial control systems advisory for Johnson Controls OpenBlue Employee, warning that versions through V2025.3.1 contain three web-application flaws that could let an attacker upload malicious files, run stored cross-site scripting attacks, or inject arbitrary HTML into affected deployments.
The July 30 advisory, republishing Johnson Controls security advisory JCI-PSA-2026-09, identifies CVE-2026-21662, CVE-2026-34495, and CVE-2026-34497. The issues carry a combined CVSS v3 score of 2.4, but the low base score should not be read as a reason to ignore exposed systems: OpenBlue Employee is used in facility-management environments across commercial facilities, government, transportation, energy, and manufacturing organizations.
Administrators should treat OpenBlue Employee (FMS Employee) V2025.3.1 and earlier as affected and contact Johnson Controls for the applicable remediation path. The advisory does not report known public exploitation as of July 30.
The three issues span file-upload handling and browser-side content sanitization. In practice, that means a successful attack may depend on a user viewing attacker-controlled content in the application, while the dangerous file-upload flaw could create a more direct route to hosting unwanted content or payloads within a trusted facility-management environment.
For Windows administrators supporting the application stack, the practical work is to identify every OpenBlue Employee instance, confirm its installed version, review internet-facing reverse proxies and remote-access paths, and check application logs for unusual uploads or suspicious content submissions. Teams should also review which accounts can upload files or manage employee-facing content, especially shared administrative accounts.
Johnson Controls reported the vulnerabilities to CISA. With no public exploitation identified, this is still a remediation and exposure-reduction exercise—not an incident declaration—but organizations running V2025.3.1 or earlier should not leave it in the routine patch queue.
The July 30 advisory, republishing Johnson Controls security advisory JCI-PSA-2026-09, identifies CVE-2026-21662, CVE-2026-34495, and CVE-2026-34497. The issues carry a combined CVSS v3 score of 2.4, but the low base score should not be read as a reason to ignore exposed systems: OpenBlue Employee is used in facility-management environments across commercial facilities, government, transportation, energy, and manufacturing organizations.
The affected ceiling is V2025.3.1
Administrators should treat OpenBlue Employee (FMS Employee) V2025.3.1 and earlier as affected and contact Johnson Controls for the applicable remediation path. The advisory does not report known public exploitation as of July 30.The three issues span file-upload handling and browser-side content sanitization. In practice, that means a successful attack may depend on a user viewing attacker-controlled content in the application, while the dangerous file-upload flaw could create a more direct route to hosting unwanted content or payloads within a trusted facility-management environment.
Internet exposure is the immediate operational concern
CISA’s guidance is familiar but particularly relevant for building and facilities platforms: keep control-system assets off the public internet, place operational networks and remote devices behind firewalls, and isolate them from ordinary business networks. Where remote access is necessary, use a maintained VPN and ensure the endpoint devices connecting through it are also secured.For Windows administrators supporting the application stack, the practical work is to identify every OpenBlue Employee instance, confirm its installed version, review internet-facing reverse proxies and remote-access paths, and check application logs for unusual uploads or suspicious content submissions. Teams should also review which accounts can upload files or manage employee-facing content, especially shared administrative accounts.
Johnson Controls reported the vulnerabilities to CISA. With no public exploitation identified, this is still a remediation and exposure-reduction exercise—not an incident declaration—but organizations running V2025.3.1 or earlier should not leave it in the routine patch queue.
References
- Primary source: CISA
Published: 2026-07-30T12:00:00+00:00
Johnson Controls OpenBlue Employee | CISA
www.cisa.gov