Cyber Resilience
← All news
Confirmed

Johnson Controls OpenBlue Employee

Our takeJohnson Controls fixed file upload, stored XSS, and HTML injection flaws in OpenBlue Employee <=2025.3.1 (CVEs-2026-21662, -34495, -34497). Update to a fixed release.
Sources (3)
What this means for you — Security leader:Update OpenBlue Employee (FMS Employee) to a version newer than 2025.3.1 to address three vulnerabilities that allow arbitrary file upload, stored XSS, and HTML injection.
What this means for you — Lean IT orgs:If you use Johnson Controls OpenBlue Employee, update it past version 2025.3.1 right away. These flaws let attackers upload bad files or run harmful scripts.
What this means for you — MSP:Check client environments for Johnson Controls OpenBlue Employee <=2025.3.1 and update to a newer release; the three vulnerabilities permit file upload and stored XSS attacks.
What this means for you — Researcher:Review the CSAF and CISA advisory for technical details on CVE-2026-21662, CVE-2026-34495, and CVE-2026-34497 in OpenBlue Employee <=2025.3.1.