PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-34499 Johnson Controls CVE debrief

CVE-2026-34499 is a high-severity vulnerability in Johnson Controls' ADVMS, with a CVSS score of 8.5. The vulnerability is caused by the use of a hard-coded cryptographic key, allowing an attacker to read sensitive constants within an executable. This issue affects ADVMS versions before 3.10. Defenders should assess exposure and prioritize remediation based on the vendor's security advisories. The CVE record and source item provide limited information about the vulnerability, and defenders should verify the affected versions of ADVMS in their inventory.

Vendor
Johnson Controls
Product
ADVMS
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Johnson Controls' ADVMS systems, including operators, platform administrators, vulnerability management teams, and security teams, should assess exposure to this vulnerability and prioritize remediation. They should verify the affected versions of ADVMS in their inventory and review the vendor's security advisories for guidance on mitigation and remediation.

Why it matters

CVE-2026-34499 is a high-severity vulnerability in Johnson Controls' ADVMS that allows an attacker to read sensitive constants within an executable. Defenders should prioritize verifying the affected versions of ADVMS in their inventory and assessing exposure to this vulnerability.

  • Verify the version of ADVMS in your inventory and check if it is affected by this vulnerability.
  • Assess exposure to this vulnerability and prioritize remediation.
  • Monitor for any updates from Johnson Controls regarding this vulnerability.

Technical summary

The vulnerability is caused by the use of a hard-coded cryptographic key in Johnson Controls' ADVMS, allowing an attacker to read sensitive constants within an executable. This issue affects ADVMS versions before 3.10. The vulnerability has a high CVSS score of 8.5, indicating a significant risk to affected systems. Defenders should prioritize verifying the affected versions of ADVMS in their inventory and assessing exposure to this vulnerability.

Defensive priority

Defenders should prioritize verifying the affected versions of ADVMS in their inventory and assessing exposure to this vulnerability.

Recommended defensive actions

  • Verify the version of ADVMS in your inventory and check if it is affected by this vulnerability.
  • Assess exposure to this vulnerability and prioritize remediation.
  • Monitor for any updates from Johnson Controls regarding this vulnerability.

Evidence notes

The CVE record and source item provide limited information about the vulnerability. The vendor, Johnson Controls, has provided a reference to their security advisories page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-34499 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-34499

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-34499 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34499

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-34499

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/34xxx/CVE-2026-34499.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.