Johnsoncontrols Johnsoncontrols

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Johnsoncontrols product.

RSS Feeds for Johnsoncontrols security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Johnsoncontrols products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Johnsoncontrols Sorted by Most Security Vulnerabilities since 2018

Johnsoncontrols Easyio Fs327 vulnerabilities

Johnsoncontrols Victor Web2 vulnerabilities

Johnsoncontrols Airwall2 vulnerabilities

Johnsoncontrols T20001 vulnerability

Johnsoncontrols Tl2801 vulnerability

Johnsoncontrols Ac20001 vulnerability

Johnsoncontrols Easyio Fg1 vulnerability

By the Year

In 2026 there have been 26 vulnerabilities in Johnsoncontrols with an average score of 6.4 out of ten. Johnsoncontrols did not have any published security vulnerabilities last year. That is, 26 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 26 6.42
2025 0 0.00
2024 7 7.10
2023 6 6.53
2022 13 7.23
2021 7 7.51
2020 6 8.03
2019 3 8.67
2018 1 4.30

It may take a day or so for new Johnsoncontrols vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Johnsoncontrols Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-34498 Oct 06, 2026
Johnson Controls Illustra L4L China <=6.0.0.66394 Cmd Injection Improper input validation vulnerability in Johnson Controls Illustra Standard - L4L China on Windows allows OS Command Injection. This issue affects Illustra Standard - L4L China: before 6.0.0.66394.
Illustra Standard L4l China
CVE-2026-27873 Oct 01, 2026
Hard-coded Creds in Johnson Controls EasyIO FG < 2.0b52 (Password Spraying) - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
Easyio Fg
CVE-2026-64893 Oct 01, 2026
Cleartext Transmission in Johnson Controls EasyIO NEO <3.3b25 (MITM) - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
Easyio Neo
CVE-2026-64892 Oct 01, 2026
Johnson Controls Easy IO Neo <3.3b63 Data Leak via Resource Paths - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.
Easy Io Neo
CVE-2026-34494 Oct 01, 2026
On-Chip Debug Interface CVE-2026-34494: Neo Series MVP2 <3.3b63 Data Leak - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.
Neo Series Mvp2
CVE-2026-34493 Oct 01, 2026
CVE-2026-34493: EasyIO FS32 <3.3b63 On-Chip Debug Data Leak - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.
Easyio Fs32
CVE-2026-71449 Oct 01, 2026
EasyIO FS32 Hard-Coded Key: Retrieve Sensitive Data before 3.0b63 : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
Easyio Fs32
CVE-2026-71448 Oct 01, 2026
Johnson Controls EasyIO FS32 Auth Abuse via Insecure Init (before 3.0b63) : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.
Easyio Fs32
CVE-2026-71453 Oct 01, 2026
Johnson Controls EasyIO FS32 File Path Traversal Vulnerability <3.0b63 - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
Easyio Fs32
CVE-2026-71452 Oct 01, 2026
OS Command Injection in Johnson Controls EasyIO FS32 before 3.0b63 - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
Easyio Fs32
CVE-2026-71451 Oct 01, 2026
OS Command Injection in Johnson Controls EasyIO FS32 <3.0b63 - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.
Easyio Fs32
CVE-2026-27874 Oct 01, 2026
Johnson Controls EasyIO FS32-before3.0b63 Hard-coded Credentials Exploit : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
Easyio Fs32
CVE-2026-27872 Oct 01, 2026
Easy IO FG <2.0b52 Improper Privilege Mgmt (Brute Force) - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
Easy Io Fg
CVE-2026-64896 Aug 27, 2026
Johnson Controls T2000 Debug & Test Interface ACL Bypass, pre-31.6 Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
T2000
CVE-2026-34491 Aug 24, 2026
Johnson Controls Metasys 14/15 XSS before 14.1.5 / 15.0.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.
Metasys 14
Metasys 15
CVE-2026-27875 Aug 21, 2026
Cleartext Sensitive Data in Simplex IM/AFA <2.01.05 (CVE-2026-27875) Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
Simplex Incident Manager Autocall Fire Administrator
CVE-2026-34492 Aug 14, 2026
Airwall before 4.1: External Control File Path Vulnerability External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.
Airwall
CVE-2026-64887 Aug 14, 2026
Hardcoded Crypto Key in Johnson Controls Airwall before 4.1 CRYPTANALYTIC ATTACK Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.
Airwall
CVE-2026-27871 Aug 14, 2026
TL280 <5.63: Broken Crypto (CWE327) Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63.
Tl280
CVE-2026-34497 Jul 31, 2026
XSS in Johnson Controls FM Systems Employee before 2025.3.1 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
Fm Systems Employee
CVE-2026-34495 Jul 31, 2026
Johnson Controls FM Systems Employee Stored XSS before 2025.3.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.
Fm Systems Employee
CVE-2026-21662 Jul 31, 2026
FM Systems Employee (before 2025.3.1) Unrestricted File Upload Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
Fm Systems Employee
CVE-2026-34490 Jul 31, 2026
Cleartext Storage of Sensitive Data in Johnson Controls XAAP App <1.53 (Android) Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.
Xaap Application
CVE-2026-34496 Jul 23, 2026
Johnson Controls victor Web before 7.1 CVE-2026-34496 CWE-269 Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.
Victor Web
CVE-2026-21655 Jul 23, 2026
Deserialization Vulnerability in Johnson Controls Victor <3.0 (Windows) Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
Ccure 9000
Victor Application Server
CVE-2026-21661 May 06, 2026
JohnsonControls AC2000 Config Search Path Injection (<10.6,<11.0,<12) Windows An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.
Ac2000
CVE-2024-32758 Aug 01, 2024
exacqVision Client/Server: Weak Key Length in TLS Handshake Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
Exacqvision Server
Exacqvision Client
CVE-2024-32862 Aug 01, 2024
ExacqVision Web Services CORS misconfiguration allows cross-origin access Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
Exacqvision Web Service
CVE-2024-32865 Aug 01, 2024
exacqVision SSL Cert Validation Bypass (CVE-2024-32865) Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
Exacqvision Server
CVE-2024-32931 Aug 01, 2024
ExacqVision Web Service Exposes Auth Tokens in Traces Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
Exacqvision Web Service
CVE-2024-32863 Aug 01, 2024
exacqVision Web Services CSRF Vulnerability Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
Exacqvision Web Service
CVE-2024-32864 Aug 01, 2024
exacqVision Web Services HTTPS enforcement bypass Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
Exacqvision Web Service
CVE-2024-0912 Jun 06, 2024
IIS Log Disclosure: WinCreds Exposed in CCURE 9000 Web Server Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the CCURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces CCURE 9000 or prior versions
Software House C Cure 9000 Siteserver
CVE-2023-3749 Aug 03, 2023
VideoEdge Local Config Edit Permits Operation Interference A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
Videoedge
CVE-2023-2024 May 18, 2023
Improper Auth in OpenBlue Data Collector <3.2.5.75 (Unauthorized Access) Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
Openblue Enterprise Manager Data Collector
CVE-2023-2025 May 18, 2023
OpenBlue E M Data Collector <3.2.5.75: Info Disclosure to Unauth Users OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
Openblue Enterprise Manager Data Collector
CVE-2022-21939 Feb 09, 2023
Johnson Controls SCT v14/v15 Sensitive Cookie Lacking HttpOnly Flag Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Metasys System Configuration Tool
CVE-2022-21940 Feb 09, 2023
Johnson Controls SCT Sensitive Cookie missing Secure before 14.2.3/15.0.3 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Metasys System Configuration Tool
CVE-2021-36204 Jan 13, 2023
IPC in Johnson Controls Metasys <10.1.6 / <11.0.3 Exposes Credentials Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
Metasys Application Data Server
Metasys Extended Application Data Server
Metasys Open Application Server
And others...
CVE-2021-36206 Oct 28, 2022
CEVAS <1.01.46: Auth Bypass via SQLi All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
Cevas
CVE-2022-21936 Oct 07, 2022
Metasys ADX 12.0 MVE SMP UI Password Bypass On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
Metasys Extended Application Data Server
CVE-2021-36200 Jul 22, 2022
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users. Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
Metasys Open Application Server
Metasys Extended Application Data Server
Metasys Application Data Server
And others...
CVE-2022-21938 Jun 15, 2022
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.
Metasys Open Application Server
Metasys Application Data Server
Metasys Extended Application Data Server
And others...
CVE-2022-21935 Jun 15, 2022
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
Metasys Open Application Server
Metasys Application Data Server
Metasys Extended Application Data Server
And others...
CVE-2022-21937 Jun 15, 2022
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.
Metasys Open Application Server
Metasys Application Data Server
Metasys Extended Application Data Server
And others...
CVE-2022-21934 May 06, 2022
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2. Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.
Metasys Open Application Server
Metasys Extended Application Data Server
Metasys Application Data Server
And others...
CVE-2021-36207 Apr 29, 2022
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
Metasys Open Application Server
Metasys Extended Application Data Server
Metasys Application Data Server
And others...
CVE-2021-36203 Apr 22, 2022
The affected product may The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.
Metasys System Configuration Tool
CVE-2021-36205 Apr 15, 2022
Under certain circumstances the session token is not cleared on logout. Under certain circumstances the session token is not cleared on logout.
Metasys Application Data Server
Metasys Extended Application Data Server
Metasys Open Application Server
And others...
CVE-2022-26643 Apr 13, 2022
An issue in EasyIO CPT Graphics v0.8 An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
Easyio Cpt Graphics
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.