← All Advisories

CVE-2026-34499

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-34499

Key Details

CVECVE-2026-34499
CVSS Score / Version8.5 (High) / CVSS v4.0
Updated2026-10-08
Affected productsJohnson Controls ADVMS
Classified asCWE-321 (Use of Hard-coded Cryptographic Key)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsADVMS
SubsystemsGeneral OT
SectorsMultiple

What to Know

Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable.

This issue affects ADVMS: before 3.10. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-34499
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-34499