← All Advisories

CVE-2026-21662

Status: UPDATED  |  Advisory ID: CVE-2026-21662

Key Details

CVECVE-2026-21662
CVSSCVSS 9.8 (Critical).
Affected productsJohnson Controls FMS Employee
Classified asCWE-434 (Unrestricted Upload of File with Dangerous Type)

What to Know

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.

This issue affects FM Systems Employee: before 2025.3.1.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21662
Vendor advisoryhttps://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories