SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-21662

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The FM Systems Employee application from Johnson Controls is vulnerable to unrestricted file upload, allowing attackers to upload malicious files that could compromise the system. Organizations using versions prior to 2025.3.1 should prioritize addressing this vulnerability to prevent potential exploitation and data breaches. Immediate action is recommended to mitigate risks associated with this security flaw.

CVE
CVE-2026-21662
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)