← All Advisories

CVE-2026-21661

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-21661

Key Details

CVECVE-2026-21661
CVSS Score / Version8.4 (High) / CVSS v4.0
Updated2026-08-24
Affected productsJohnson Controls AC2000
Classified asCWE-427 (Uncontrolled Search Path Element)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Johnson ControlsAC2000
SubsystemsGeneral OT
SectorsMultiple

What to Know

An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths.

This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3. (NVD)

What to Do

Monitor Johnson Controls's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21661
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21661