PatchSiren cyber security CVE debrief
CVE-2026-21658 Unknown Vendor CVE debrief
CVE-2026-21658 is a critical pre-authentication issue in Johnson Controls, Inc. Frick Controls Quantum HD. CISA’s advisory says insufficient validation of input in certain parameters may permit unexpected actions before authentication occurs. The supplied CVSS v3.1 vector rates the issue 9.1/CRITICAL with no privileges or user interaction required and high integrity and availability impact.
- Vendor
- Unknown Vendor
- Product
- Johnson Controls, Inc. Frick Controls Quantum HD <=10.22
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-26
- Original CVE updated
- 2026-02-26
- Advisory published
- 2026-02-26
- Advisory updated
- 2026-02-26
Who should care
OT and ICS asset owners, plant operators, control system engineers, and security teams responsible for Frick Controls Quantum HD deployments and supporting infrastructure.
Technical summary
The CISA CSAF advisory (ICSA-26-057-01) describes insufficient input validation in certain parameters of Frick Controls Quantum HD. The advisory indicates the flaw may allow unexpected actions prior to authentication. The supplied scoring is CVSS v3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H (9.1, critical).
Defensive priority
Immediate. This is a critical, pre-authentication issue in an industrial control product, so affected environments should prioritize upgrade planning and exposure reduction now.
Recommended defensive actions
- Inventory all Frick Controls Quantum HD systems and identify any legacy installations covered by the advisory.
- Upgrade to Quantum HD Unity version 12 or later using Johnson Controls' documented update procedure.
- After upgrading, verify compliance with the vendor hardening guide and apply the recommended security configurations.
- Review Johnson Controls Product Security Advisory JCI-PSA-2026-05 for additional mitigation guidance.
- Use CISA ICS recommended practices and defense-in-depth guidance to reduce exposure while remediation is underway.
- Validate backups and recovery procedures before making changes to production OT systems.
Evidence notes
Source evidence comes from CISA's CSAF advisory ICSA-26-057-01, published 2026-02-26 and listed in the corpus as the initial publication with no later revision. The source notes the issue can impact the device before authentication occurs and includes SSVCv2/E:N/A:Y dated 2026-02-25T07:00:00Z. The supplied enrichment shows no KEV listing.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21658 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21658
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21658 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21658
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.