PatchSiren cyber security CVE debrief
CVE-2026-21662 Johnson Controls CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T18:17:13.650Z and has not been modified since then. CVE-2026-21662 is a medium-severity vulnerability in Johnson Controls FM Systems Employee before version 2025.3.1, allowing unrestricted file uploads with dangerous types. This issue affects FM Systems Employee, potentially leading to security risks. Organizations should verify their version and apply necessary updates to mitigate risks. Security teams should prioritize this vulnerability due to its potential impact on system security.
- Vendor
- Johnson Controls
- Product
- FM Systems Employee
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Organizations using Johnson Controls FM Systems Employee should verify their version and apply the necessary updates to mitigate potential risks. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. Additionally, checking relevant monitoring, detection, and logs for exposed assets that need extra review is crucial. Security teams and operators should prioritize this vulnerability due to its potential impact on system security and the need for immediate action to prevent exploitation.
Technical summary
CVE-2026-21662 is a medium-severity vulnerability in Johnson Controls FM Systems Employee before version 2025.3.1. The issue allows for unrestricted file uploads with dangerous types, potentially leading to security risks. This vulnerability requires attention due to potential file upload risks and the need for verifying FM Systems Employee version and applying 2025.3.1 or later if vulnerable.
Defensive priority
Medium-priority vulnerability with a CVSS score of 4.8, requiring attention due to potential file upload risks.
Recommended defensive actions
- Verify FM Systems Employee version and apply 2025.3.1 or later if vulnerable
- Restrict file uploads to only allow specific, safe file types
- Implement additional security measures to monitor and control file uploads
Evidence notes
The evidence for this vulnerability is limited. Verification of vendor remediation and affected scope is needed. Johnson Controls FM Systems Employee vulnerability before version 2025.3.1 allows unrestricted file uploads with dangerous types. Further review of the official advisory and CVE record is recommended to validate affected scope, severity, and vendor guidance.
Official resources
-
CVE-2026-21662 CVE record
CVE.org
-
CVE-2026-21662 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T18:17:13.650Z and has not been modified since then.