Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Johnsoncontrols

First CVE: Jul 16, 2012Active for: 14 yearsTotal CVEs: 69
40.2
VTI Score
Medium

Johnson Controls operates a broadly represented portfolio of building management, automation, and surveillance systems that play a foundational role in physical-infrastructure operations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating across its MetaSys application servers and building-control middleware as well as its ExacqVision surveillance platform. The exposure recurs through authentication and access-control weaknesses—improper authentication, privilege-management flaws, and cross-site scripting in web-facing components—that are characteristic of legacy and modernized enterprise control software integrating operational technology and IT systems. Defenders should treat this vendor's critical disclosures as high-priority for any deployed building-management infrastructure and establish patch-management workflows suited to operational-technology environments where downtime carries facility-wide consequences. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
69
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Johnsoncontrols over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2012
14 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(113 total)

Top CVEs

Signals from CVEs in this vendor scope (69 CVEs).

69 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-9047HIGH
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and
Jun 26, 20207.238NOYES
CVE-2026-21658CRITICAL
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injectio
Feb 27, 20269.833NONO
CVE-2026-21660CRITICAL
Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to una
Feb 27, 20269.832NONO
CVE-2026-21659CRITICAL
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthentica
Feb 27, 20269.832NONO
CVE-2026-21657CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in cer
Feb 27, 20269.832NONO
CVE-2026-21654CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. 
Feb 27, 20269.832NONO
CVE-2023-2024HIGH
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
May 18, 20237.532NONO
CVE-2026-21656CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in cer
Feb 27, 20269.830NONO
CVE-2022-21941CRITICAL
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
Aug 31, 20229.830NONO
CVE-2021-36205CRITICAL
Under certain circumstances the session token is not cleared on logout.
Apr 15, 20229.830NONO
View all 69 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products69 CVEs
32%
38%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCriticalUnknown
Attack Vector
Local4 (5.8%)
Network55 (79.7%)
Unknown5 (7.2%)
Physical0 (0.0%)
Adjacent Network5 (7.2%)
Attack Complexity
Low61 (88.4%)
High3 (4.3%)
Unknown5 (7.2%)
User Interaction
None51 (73.9%)
Unknown5 (7.2%)
Required13 (18.8%)
Privileges Required
Low16 (23.2%)
High2 (2.9%)
None46 (66.7%)
Unknown5 (7.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (69 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.4% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Johnsoncontrols.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Johnsoncontrols — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Johnsoncontrols's Products

View all 4 CNAs →

Top CWEs