PatchSiren cyber security CVE debrief
CVE-2026-21660 Unknown Vendor CVE debrief
CVE-2026-21660 affects Frick Controls Quantum HD and is caused by hardcoded credentials that can lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise. CISA published the advisory as ICSA-26-057-01 on 2026-02-26 and recommends upgrading to Quantum HD Unity version 12 or higher.
- Vendor
- Unknown Vendor
- Product
- Johnson Controls, Inc. Frick Controls Quantum HD <=10.22
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-27
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-02-27
- Advisory updated
- 2026-08-24
Who should care
Owners and operators of Frick Controls Quantum HD deployments, OT/ICS security teams, plant engineers, and integrators supporting affected Quantum HD systems should review this advisory.
Technical summary
The advisory describes an access-control weakness caused by hardcoded credentials in Frick Controls Quantum HD. The supplied CVSS 3.1 vector is AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating high confidentiality impact with no integrity or availability impact in the score. The advisory also uses SSVCv2 notation with Exploitation: None and Automatable: None at publication time. Remediation guidance states that the affected Quantum HD platforms are legacy and end of support, and that operators should upgrade to Quantum HD Unity version 12 or higher, then verify compliance with the hardening guide and recommended security configurations.
Defensive priority
Medium to high for OT environments. Although the CVSS score is medium, hardcoded credentials in a legacy, end-of-support industrial control platform justify prompt remediation, especially where the affected system is operationally important.
Recommended defensive actions
- Upgrade affected Frick Controls Quantum HD installations to Quantum HD Unity version 12 or higher using the vendor’s update procedure.
- After upgrading, verify full compliance with the hardening guide and apply all recommended security configurations.
- Review related OT access-control practices to ensure hardcoded credentials or other embedded secrets are not left in use.
- Consult Johnson Controls Product Security Advisory JCI-PSA-2026-05 for additional mitigation guidance and coordinate changes with operations before making updates.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-057-01 and the official CVE record. The advisory explicitly states that hardcoded credentials in Frick Controls Quantum HD can cause unauthorized access, exposure of sensitive information, and potential misuse or system compromise. The remediation section recommends upgrading to Quantum HD Unity version 12 or higher and references Johnson Controls Product Security Advisory JCI-PSA-2026-05. No KEV entry is present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21660 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21660
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21660 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21660
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.