Status: UPDATED | Advisory ID: CVE-2026-34499
| CVE | CVE-2026-34499 |
| CVSS Score / Version | 8.5 (High) / CVSS v4.0 |
| Updated | 2026-10-08 |
| Affected products | Johnson Controls ADVMS |
| Classified as | CWE-321 (Use of Hard-coded Cryptographic Key) |
| Exploitation prediction (EPSS) | 0.10% probability of exploitation in the next 30 days (1% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Johnson Controls | ADVMS |
| Subsystems | General OT |
| Sectors | Multiple |
Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable.
This issue affects ADVMS: before 3.10. (NVD)
Monitor Johnson Controls's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-34499 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-34499 |