PatchSiren cyber security CVE debrief
CVE-2026-21654 Unknown Vendor CVE debrief
CVE-2026-21654 affects Johnson Controls Frick Controls Quantum HD versions up to 10.22. According to CISA, insufficient validation of input in certain parameters may permit unexpected actions before authentication occurs. The advisory was published on 2026-02-26 and assigns a critical CVSS 3.1 score of 9.1. CISA recommends upgrading legacy systems to Quantum HD Unity version 12 or later.
- Vendor
- Unknown Vendor
- Product
- Johnson Controls, Inc. Frick Controls Quantum HD <=10.22
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
OT and industrial control system owners, plant operators, controls engineers, system integrators, and security teams responsible for Frick Controls Quantum HD deployments, especially environments still running legacy versions 10.22 through 11.
Technical summary
The supplied advisory describes a pre-authentication weakness in Frick Controls Quantum HD where certain inputs are not sufficiently validated, allowing unexpected actions that could affect device security. The advisory identifies affected legacy platforms as versions 10.22 through 11, with remediation centered on upgrading to Quantum HD Unity version 12 or higher and then applying the vendor hardening guidance. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H.
Defensive priority
High. This is a critical, network-reachable, pre-authentication issue on an OT product line that the advisory says is legacy and end-of-support. Prioritize patch planning, upgrade execution, and compensating controls for exposed or reachable devices.
Recommended defensive actions
- Upgrade Frick Controls Quantum HD legacy systems to Quantum HD Unity version 12 or higher using the vendor update procedure referenced in the advisory.
- After upgrading, verify compliance with the hardening guide and apply all recommended security configurations.
- Review network exposure and restrict access to affected OT devices to only required management and operational paths.
- Use the CISA advisory and Johnson Controls security advisory to confirm product scope, supported versions, and remediation steps before change windows.
- Document any systems that cannot be upgraded immediately and apply compensating controls while tracking them for remediation.
Evidence notes
The debrief is based only on the supplied CISA CSAF advisory data for ICSA-26-057-01 / CVE-2026-21654. The source states the issue is due to insufficient input validation, can affect security before authentication, and rates severity at CVSS 9.1. It also states the affected legacy platforms are end of support and recommends upgrading to Quantum HD Unity version 12 or higher. No KEV listing or ransomware-campaign linkage is present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21654 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21654
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21654 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21654
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.