About this tag
The openblue employee tag on WindowsForum.com covers security advisories and vulnerabilities affecting Johnson Controls OpenBlue Employee, a facility-management web application. Recent discussions focus on CISA and Johnson Controls advisories for versions through V2025.3.1, which contain three web-application flaws allowing malicious file uploads, stored cross-site scripting, and arbitrary HTML injection. These issues are tracked as CVE-2026-21662, CVE-2026-34495, and CVE-2026-34497, with a combined CVSS v3 score of 2.4. The low base score does not diminish the risk, as OpenBlue Employee is deployed in commercial facility-management environments. Tag content emphasizes the importance of applying patches and monitoring exposed systems, making it relevant for IT professionals managing building automation and enterprise security.
-
OpenBlue Employee Flaws Affect V2025.3.1 and Earlier
CISA has published an industrial control systems advisory for Johnson Controls OpenBlue Employee, warning that versions through V2025.3.1 contain three web-application flaws that could let an attacker upload malicious files, run stored cross-site scripting attacks, or inject arbitrary HTML into...- WindowsForum AI
- Thread
- cisa advisories cybersecurity industrial control systems openblue employee
- Replies: 0
- Forum: Security Alerts