PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21661 JohnsonControls CVE debrief

CVE-2026-21661 is a publicly disclosed DLL hijacking vulnerability in Johnson Controls CEM AC2000. According to CISA’s advisory, a local attacker could use the issue to escalate standard user privileges on the host machine. The supplied CVSS vector and score place this at 8.7 (HIGH), reflecting a local attack with no user interaction and high impact to confidentiality and integrity.

Vendor
JohnsonControls
Product
Johnson Controls Inc. CEM AC2000 12.0 11.0 10.6
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-06
Original CVE updated
2026-08-24
Advisory published
2026-05-06
Advisory updated
2026-08-24

Who should care

Organizations running Johnson Controls CEM AC2000 on Windows hosts should pay attention, especially endpoint, IT, and OT teams responsible for application deployment, least-privilege controls, and patch management. Security teams should also review any local user accounts that can launch or influence the application.

Technical summary

CISA describes the flaw as DLL hijacking in Johnson Controls CEM AC2000. The supplied CVSS 3.1 vector is AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L, which indicates a local attack that requires low privileges, no user interaction, and can cross a security boundary. The practical security concern is that an attacker with standard user access on the host may be able to influence library loading and escalate privileges.

Defensive priority

High. The issue is locally exploitable, affects an industrial access-control product, and has vendor-recommended fixes available for all affected branches.

Recommended defensive actions

  • Upgrade CEM AC 2000 12.0 to 12.0 Release 10.
  • Upgrade CEM AC 2000 11.0 to 11.0 Release 9.
  • Upgrade CEM AC 2000 10.6 to 10.6 Release 3.
  • Follow Johnson Controls' Product Security Advisory for the full mitigation guidance.
  • Review Windows host hardening and least-privilege controls for systems running AC2000.
  • Inventory exposed or user-accessible AC2000 installations and prioritize remediation on those hosts.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-26-125-05 / CVE-2026-21661, published and modified on 2026-05-05. The advisory states: 'The affected product is vulnerable to DLL hijacking, which could allow an attacker to escalate standard user privileges on the host machine.' The remediation section lists version-specific upgrades for CEM AC2000 12.0, 11.0, and 10.6. No KEV listing was included in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-21661 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-21661

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-21661 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21661

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-125-05.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-05

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.