PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-26385 Johnson Controls CVE debrief

CVE-2025-26385 is a critical Johnson Controls Metasys vulnerability that, under certain circumstances, could allow remote SQL execution. CISA’s CSAF republication covers Metasys Application and Data Server (ADS), Extended Application and Data Server (ADX), LCS8500, NAE8500, System Configuration Tool (SCT), and Controller Configuration Tool (CCT). The advisory directs defenders to apply Johnson Controls’ patch, harden and segment Metasys deployments, and restrict exposure of TCP port 1433.

Vendor
Johnson Controls
Product
Metasys Application and Data Server (ADS)
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-27
Original CVE updated
2026-01-27
Advisory published
2026-01-27
Advisory updated
2026-01-27

Who should care

Industrial control system owners and operators using Johnson Controls Metasys products, especially administrators responsible for ADS, ADX, LCS8500, NAE8500, SCT, or CCT deployments. Teams with Metasys systems reachable from less trusted networks or deployed without strong segmentation should prioritize review.

Technical summary

The advisory describes a vulnerability that can permit remote SQL execution under certain circumstances. The source corpus identifies affected Metasys products as ADS, ADX, LCS8500, NAE8500, SCT, and CCT. Johnson Controls’ mitigation guidance includes installing the Metasys patch for GIV-165989, following the Metasys Release 14 Hardening Guide, and closing incoming TCP port 1433 to reduce exposure.

Defensive priority

Urgent. This is a CVSS 10.0 critical issue in an ICS product line with vendor guidance to patch and reduce network exposure. Treat internet-facing or weakly segmented deployments as highest priority.

Recommended defensive actions

  • Apply the Johnson Controls Metasys patch for GIV-165989 from the License Portal.
  • Review the Metasys Release 14 Hardening Guide and confirm each installation is on a segmented network.
  • Ensure Metasys systems are not exposed to untrusted networks, including the internet.
  • Close incoming TCP port 1433 where operationally feasible to reduce exploitation risk.
  • Verify whether any of the affected products listed in the advisory are present in your environment.
  • Use the Johnson Controls Product Security Advisory JCI-PSA-2026-02 for additional mitigation details.

Evidence notes

All material facts in this debrief are drawn from the supplied CISA CSAF source item for ICSA-26-027-04 and its cited Johnson Controls mitigation guidance. The corpus states that successful exploitation could allow remote SQL execution and lists the affected Metasys products plus the vendor-recommended mitigations. No exploit steps, reproduction details, or unsupported claims are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-26385 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-26385

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-26385 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26385

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.