PatchSiren cyber security CVE debrief
CVE-2026-34499 Johnson Controls CVE debrief
CVE-2026-34499 is a high-severity vulnerability in Johnson Controls' ADVMS, with a CVSS score of 8.5. The vulnerability is caused by the use of a hard-coded cryptographic key, allowing an attacker to read sensitive constants within an executable. This issue affects ADVMS versions before 3.10. Defenders should assess exposure and prioritize remediation based on the vendor's security advisories. The CVE record and source item provide limited information about the vulnerability, and defenders should verify the affected versions of ADVMS in their inventory.
- Vendor
- Johnson Controls
- Product
- ADVMS
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Johnson Controls' ADVMS systems, including operators, platform administrators, vulnerability management teams, and security teams, should assess exposure to this vulnerability and prioritize remediation. They should verify the affected versions of ADVMS in their inventory and review the vendor's security advisories for guidance on mitigation and remediation.
Why it matters
CVE-2026-34499 is a high-severity vulnerability in Johnson Controls' ADVMS that allows an attacker to read sensitive constants within an executable. Defenders should prioritize verifying the affected versions of ADVMS in their inventory and assessing exposure to this vulnerability.
- Verify the version of ADVMS in your inventory and check if it is affected by this vulnerability.
- Assess exposure to this vulnerability and prioritize remediation.
- Monitor for any updates from Johnson Controls regarding this vulnerability.
Technical summary
The vulnerability is caused by the use of a hard-coded cryptographic key in Johnson Controls' ADVMS, allowing an attacker to read sensitive constants within an executable. This issue affects ADVMS versions before 3.10. The vulnerability has a high CVSS score of 8.5, indicating a significant risk to affected systems. Defenders should prioritize verifying the affected versions of ADVMS in their inventory and assessing exposure to this vulnerability.
Defensive priority
Defenders should prioritize verifying the affected versions of ADVMS in their inventory and assessing exposure to this vulnerability.
Recommended defensive actions
- Verify the version of ADVMS in your inventory and check if it is affected by this vulnerability.
- Assess exposure to this vulnerability and prioritize remediation.
- Monitor for any updates from Johnson Controls regarding this vulnerability.
Evidence notes
The CVE record and source item provide limited information about the vulnerability. The vendor, Johnson Controls, has provided a reference to their security advisories page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34499 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34499
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34499 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34499
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-34499
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/34xxx/CVE-2026-34499.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.