Johnsoncontrols
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Johnsoncontrols product.
RSS Feeds for Johnsoncontrols security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Johnsoncontrols products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Johnsoncontrols Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 26 vulnerabilities in Johnsoncontrols with an average score of 6.4 out of ten. Johnsoncontrols did not have any published security vulnerabilities last year. That is, 26 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 26 | 6.42 |
| 2025 | 0 | 0.00 |
| 2024 | 7 | 7.10 |
| 2023 | 6 | 6.53 |
| 2022 | 13 | 7.23 |
| 2021 | 7 | 7.51 |
| 2020 | 6 | 8.03 |
| 2019 | 3 | 8.67 |
| 2018 | 1 | 4.30 |
It may take a day or so for new Johnsoncontrols vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Johnsoncontrols Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-34498 | Oct 06, 2026 |
Johnson Controls Illustra L4L China <=6.0.0.66394 Cmd InjectionImproper input validation vulnerability in Johnson Controls Illustra Standard - L4L China on Windows allows OS Command Injection. This issue affects Illustra Standard - L4L China: before 6.0.0.66394. |
|
| CVE-2026-27873 | Oct 01, 2026 |
Hard-coded Creds in Johnson Controls EasyIO FG < 2.0b52 (Password Spraying)- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52. |
|
| CVE-2026-64893 | Oct 01, 2026 |
Cleartext Transmission in Johnson Controls EasyIO NEO <3.3b25 (MITM)- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25. |
|
| CVE-2026-64892 | Oct 01, 2026 |
Johnson Controls Easy IO Neo <3.3b63 Data Leak via Resource Paths- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63. |
|
| CVE-2026-34494 | Oct 01, 2026 |
On-Chip Debug Interface CVE-2026-34494: Neo Series MVP2 <3.3b63 Data Leak- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63. |
|
| CVE-2026-34493 | Oct 01, 2026 |
CVE-2026-34493: EasyIO FS32 <3.3b63 On-Chip Debug Data Leak- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63. |
|
| CVE-2026-71449 | Oct 01, 2026 |
EasyIO FS32 Hard-Coded Key: Retrieve Sensitive Data before 3.0b63: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63. |
|
| CVE-2026-71448 | Oct 01, 2026 |
Johnson Controls EasyIO FS32 Auth Abuse via Insecure Init (before 3.0b63): Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63. |
|
| CVE-2026-71453 | Oct 01, 2026 |
Johnson Controls EasyIO FS32 File Path Traversal Vulnerability <3.0b63- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63. |
|
| CVE-2026-71452 | Oct 01, 2026 |
OS Command Injection in Johnson Controls EasyIO FS32 before 3.0b63- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63. |
|
| CVE-2026-71451 | Oct 01, 2026 |
OS Command Injection in Johnson Controls EasyIO FS32 <3.0b63- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63. |
|
| CVE-2026-27874 | Oct 01, 2026 |
Johnson Controls EasyIO FS32-before3.0b63 Hard-coded Credentials Exploit: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63. |
|
| CVE-2026-27872 | Oct 01, 2026 |
Easy IO FG <2.0b52 Improper Privilege Mgmt (Brute Force)- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52. |
|
| CVE-2026-64896 | Aug 27, 2026 |
Johnson Controls T2000 Debug & Test Interface ACL Bypass, pre-31.6Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6. |
|
| CVE-2026-34491 | Aug 24, 2026 |
Johnson Controls Metasys 14/15 XSS before 14.1.5 / 15.0.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1. |
|
| CVE-2026-27875 | Aug 21, 2026 |
Cleartext Sensitive Data in Simplex IM/AFA <2.01.05 (CVE-2026-27875)Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05. |
|
| CVE-2026-34492 | Aug 14, 2026 |
Airwall before 4.1: External Control File Path VulnerabilityExternal control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1. |
|
| CVE-2026-64887 | Aug 14, 2026 |
Hardcoded Crypto Key in Johnson Controls Airwall before 4.1 CRYPTANALYTIC ATTACKUse of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. |
|
| CVE-2026-27871 | Aug 14, 2026 |
TL280 <5.63: Broken Crypto (CWE327)Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63. |
|
| CVE-2026-34497 | Jul 31, 2026 |
XSS in Johnson Controls FM Systems Employee before 2025.3.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1. |
|
| CVE-2026-34495 | Jul 31, 2026 |
Johnson Controls FM Systems Employee Stored XSS before 2025.3.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1. |
|
| CVE-2026-21662 | Jul 31, 2026 |
FM Systems Employee (before 2025.3.1) Unrestricted File UploadUnrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1. |
|
| CVE-2026-34490 | Jul 31, 2026 |
Cleartext Storage of Sensitive Data in Johnson Controls XAAP App <1.53 (Android)Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. |
|
| CVE-2026-34496 | Jul 23, 2026 |
Johnson Controls victor Web before 7.1 CVE-2026-34496 CWE-269Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. |
|
| CVE-2026-21655 | Jul 23, 2026 |
Deserialization Vulnerability in Johnson Controls Victor <3.0 (Windows)Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. |
|
| CVE-2026-21661 | May 06, 2026 |
JohnsonControls AC2000 Config Search Path Injection (<10.6,<11.0,<12) WindowsAn Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3. |
|
| CVE-2024-32758 | Aug 01, 2024 |
exacqVision Client/Server: Weak Key Length in TLS HandshakeUnder certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange |
|
| CVE-2024-32862 | Aug 01, 2024 |
ExacqVision Web Services CORS misconfiguration allows cross-origin accessUnder certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains. |
|
| CVE-2024-32865 | Aug 01, 2024 |
exacqVision SSL Cert Validation Bypass (CVE-2024-32865)Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices. |
|
| CVE-2024-32931 | Aug 01, 2024 |
ExacqVision Web Service Exposes Auth Tokens in TracesUnder certain circumstances the exacqVision Web Service can expose authentication token details within communications. |
|
| CVE-2024-32863 | Aug 01, 2024 |
exacqVision Web Services CSRF VulnerabilityUnder certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF) |
|
| CVE-2024-32864 | Aug 01, 2024 |
exacqVision Web Services HTTPS enforcement bypassUnder certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS) |
|
| CVE-2024-0912 | Jun 06, 2024 |
IIS Log Disclosure: WinCreds Exposed in CCURE 9000 Web ServerUnder certain circumstances the Microsoft® Internet Information Server (IIS) used to host the CCURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces CCURE 9000 or prior versions |
|
| CVE-2023-3749 | Aug 03, 2023 |
VideoEdge Local Config Edit Permits Operation InterferenceA local user could edit the VideoEdge configuration file and interfere with VideoEdge operation. |
|
| CVE-2023-2024 | May 18, 2023 |
Improper Auth in OpenBlue Data Collector <3.2.5.75 (Unauthorized Access)Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances. |
|
| CVE-2023-2025 | May 18, 2023 |
OpenBlue E M Data Collector <3.2.5.75: Info Disclosure to Unauth UsersOpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances. |
|
| CVE-2022-21939 | Feb 09, 2023 |
Johnson Controls SCT v14/v15 Sensitive Cookie Lacking HttpOnly FlagSensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie. |
|
| CVE-2022-21940 | Feb 09, 2023 |
Johnson Controls SCT Sensitive Cookie missing Secure before 14.2.3/15.0.3Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie. |
|
| CVE-2021-36204 | Jan 13, 2023 |
IPC in Johnson Controls Metasys <10.1.6 / <11.0.3 Exposes CredentialsUnder some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text. |
And others... |
| CVE-2021-36206 | Oct 28, 2022 |
CEVAS <1.01.46: Auth Bypass via SQLiAll versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries. |
|
| CVE-2022-21936 | Oct 07, 2022 |
Metasys ADX 12.0 MVE SMP UI Password BypassOn Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI. |
|
| CVE-2021-36200 | Jul 22, 2022 |
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users. |
And others... |
| CVE-2022-21938 | Jun 15, 2022 |
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 couldUnder certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface. |
And others... |
| CVE-2022-21935 | Jun 15, 2022 |
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change. |
And others... |
| CVE-2022-21937 | Jun 15, 2022 |
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 couldUnder certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface. |
And others... |
| CVE-2022-21934 | May 06, 2022 |
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2. |
And others... |
| CVE-2021-36207 | Apr 29, 2022 |
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 couldUnder certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator. |
And others... |
| CVE-2021-36203 | Apr 22, 2022 |
The affected product mayThe affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request. |
|
| CVE-2021-36205 | Apr 15, 2022 |
Under certain circumstances the session token is not cleared on logout.Under certain circumstances the session token is not cleared on logout. |
And others... |
| CVE-2022-26643 | Apr 13, 2022 |
An issue in EasyIO CPT Graphics v0.8An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application. |
|