Johnson Controls
First CVE: Jun 18, 2019Active for: 7 years
89
CVEs Published
More CVEs Published than 69% of tracked CNAs
11.1
Avg CVEs / Year
More Avg CVEs / Year than 56% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Johnson Controls over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2019
7 years ago
Most Recent CVE
Jul 23, 2026
2 days ago
Top CVEs
All CVEs published by Johnson Controls as a CNA, regardless of affected vendor or product.
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9047HIGH A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and | Jun 26, 2020 | 7.2 | 38 | NO | YES |
CVE-2026-21655HIGH Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586.
This issue affects victor: from 2.9 before 3.0. | Jul 23, 2026 | 8.7 | 36 | NO | NO |
CVE-2026-21658CRITICAL Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injectio | Feb 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-34496HIGH Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.
This issue affects victor Web: before 7.1. | Jul 23, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-21653HIGH Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application ser | Jul 23, 2026 | 7.2 | 32 | NO | NO |
CVE-2026-21660CRITICAL Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to una | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21659CRITICAL Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthentica | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21657CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in cer | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21654CRITICAL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-26385CRITICAL Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of t | Jan 30, 2026 | 9.5 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA89 CVEs
26%
45%
27%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (7.9%)
Network71 (79.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (5.6%)
Attack Complexity
Low82 (92.1%)
High7 (7.9%)
Unknown0 (0.0%)
User Interaction
None73 (82.0%)
Unknown0 (0.0%)
Required13 (14.6%)
Privileges Required
Low23 (25.8%)
High8 (9.0%)
None58 (65.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (89 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.1% of CVEs· 81st percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Johnson Controls as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Johnson Controls as a CNA — matched by CVE ID, not by organization name.