Johnson Controls operates a broadly represented portfolio of building management, automation, and surveillance systems that play a foundational role in physical-infrastructure operations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating across its MetaSys application servers and building-control middleware as well as its ExacqVision surveillance platform. The exposure recurs through authentication and access-control weaknesses—improper authentication, privilege-management flaws, and cross-site scripting in web-facing components—that are characteristic of legacy and modernized enterprise control software integrating operational technology and IT systems. Defenders should treat this vendor's critical disclosures as high-priority for any deployed building-management infrastructure and establish patch-management workflows suited to operational-technology environments where downtime carries facility-wide consequences. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Johnsoncontrols over time
Signals from CVEs in this vendor scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9047HIGH A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and | Jun 26, 2020 | 7.2 | 38 | NO | YES |
CVE-2026-21658CRITICAL Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injectio | Feb 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-21660CRITICAL Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to una | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21659CRITICAL Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthentica | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21657CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in cer | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21654CRITICAL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2023-2024HIGH Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances. | May 18, 2023 | 7.5 | 32 | NO | NO |
CVE-2026-21656CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in cer | Feb 27, 2026 | 9.8 | 30 | NO | NO |
CVE-2022-21941CRITICAL All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system. | Aug 31, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-36205CRITICAL Under certain circumstances the session token is not cleared on logout. | Apr 15, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (69 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Johnsoncontrols.
Media articles that mention a CVE ID that affects a product developed by Johnsoncontrols — matched by CVE ID, not by vendor name.