PatchSiren cyber security CVE debrief
CVE-2025-26385 Johnson Controls CVE debrief
CVE-2025-26385 is a critical Johnson Controls Metasys vulnerability that, under certain circumstances, could allow remote SQL execution. CISA’s CSAF republication covers Metasys Application and Data Server (ADS), Extended Application and Data Server (ADX), LCS8500, NAE8500, System Configuration Tool (SCT), and Controller Configuration Tool (CCT). The advisory directs defenders to apply Johnson Controls’ patch, harden and segment Metasys deployments, and restrict exposure of TCP port 1433.
- Vendor
- Johnson Controls
- Product
- Metasys Application and Data Server (ADS)
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2026-01-27
- Advisory updated
- 2026-01-27
Who should care
Industrial control system owners and operators using Johnson Controls Metasys products, especially administrators responsible for ADS, ADX, LCS8500, NAE8500, SCT, or CCT deployments. Teams with Metasys systems reachable from less trusted networks or deployed without strong segmentation should prioritize review.
Technical summary
The advisory describes a vulnerability that can permit remote SQL execution under certain circumstances. The source corpus identifies affected Metasys products as ADS, ADX, LCS8500, NAE8500, SCT, and CCT. Johnson Controls’ mitigation guidance includes installing the Metasys patch for GIV-165989, following the Metasys Release 14 Hardening Guide, and closing incoming TCP port 1433 to reduce exposure.
Defensive priority
Urgent. This is a CVSS 10.0 critical issue in an ICS product line with vendor guidance to patch and reduce network exposure. Treat internet-facing or weakly segmented deployments as highest priority.
Recommended defensive actions
- Apply the Johnson Controls Metasys patch for GIV-165989 from the License Portal.
- Review the Metasys Release 14 Hardening Guide and confirm each installation is on a segmented network.
- Ensure Metasys systems are not exposed to untrusted networks, including the internet.
- Close incoming TCP port 1433 where operationally feasible to reduce exploitation risk.
- Verify whether any of the affected products listed in the advisory are present in your environment.
- Use the Johnson Controls Product Security Advisory JCI-PSA-2026-02 for additional mitigation details.
Evidence notes
All material facts in this debrief are drawn from the supplied CISA CSAF source item for ICSA-26-027-04 and its cited Johnson Controls mitigation guidance. The corpus states that successful exploitation could allow remote SQL execution and lists the affected Metasys products plus the vendor-recommended mitigations. No exploit steps, reproduction details, or unsupported claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-26385 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-26385
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-26385 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26385
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.