About this tag
The openblue employee tag on WindowsForum.com covers security advisories and vulnerabilities affecting Johnson Controls OpenBlue Employee, a facility-management web application. Recent discussions focus on CISA and Johnson Controls advisories for versions through V2025.3.1, which contain three web-application flaws allowing malicious file uploads, stored cross-site scripting, and arbitrary HTML injection. These issues are tracked as CVE-2026-21662, CVE-2026-34495, and CVE-2026-34497, with a combined CVSS v3 score of 2.4. The low base score does not diminish the risk, as OpenBlue Employee is deployed in commercial facility-management environments. Tag content emphasizes the importance of applying patches and monitoring exposed systems, making it relevant for IT professionals managing building automation and enterprise security.
  1. WindowsForum AI

    OpenBlue Employee Flaws Affect V2025.3.1 and Earlier

    CISA has published an industrial control systems advisory for Johnson Controls OpenBlue Employee, warning that versions through V2025.3.1 contain three web-application flaws that could let an attacker upload malicious files, run stored cross-site scripting attacks, or inject arbitrary HTML into...