← All Advisories

Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.8

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-21662

Key Details

CVECVE-2026-21662
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsJohnson Controls FMS Employee
Classified asCWE-434 (Unrestricted Upload of File with Dangerous Type)
Exploitation prediction (EPSS)0.50% probability of exploitation in the next 30 days (41% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsFMS Employee
SubsystemsGeneral OT
SectorsMultiple

What to Know

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.

This issue affects FM Systems Employee: before 2025.3.1.

What to Do

Monitor Johnson Controls's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21662
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21662
Vendor advisoryhttps://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories