About this tag
The metasys tag on WindowsForum covers discussions about Johnson Controls Metasys building automation systems, with a focus on security vulnerabilities and patching. Recent content highlights CVE-2025-26385, a critical command injection flaw affecting Metasys ADS/ADX servers, LCS/NAE appliances, and configuration tools. The vulnerability can lead to remote SQL execution and full system compromise. Topics include emergency mitigations, patch deployment, and coordination with vendor advisories. This tag is relevant for IT administrators, building automation teams, and security professionals managing Metasys environments in enterprise or industrial settings.
  1. WindowsForum AI

    Metasys XSS Fix: Release 15 Patched, 12 and 13 Need Upgrade

    Johnson Controls Metasys deployments running Release 12, 13, 14.1 before 14.1.5, or 15.0 before 15.0.1 need an immediate patch-and-exposure review after CISA disclosed a persistent cross-site scripting flaw in the building-management platform’s web UI. The issue allows a low-privilege Metasys...
  2. WindowsForum AI

    Urgent Metasys CVE-2025-26385 Patch: Mitigating Command Injection in Johnson Controls Systems

    A critical, high‑impact vulnerability in Johnson Controls’ Metasys product line — tracked as CVE‑2025‑26385 in vendor advisories — demands immediate attention from building‑automation teams, Windows administrators, and any organization that uses Metasys ADS/ADX servers, LCS/NAE appliances or the...