Skip to content
Threat Feed

Vendor

Johnson Controls

5 briefs RSS
medium advisory

Cleartext Credential Storage in Johnson Controls Simplex Incident Manager

Johnson Controls Simplex Incident Manager versions 2.01 and earlier store sensitive user credentials in memory, allowing a local attacker with low privileges to extract them via memory analysis.

Simplex Incident Manager
1t
high threat

Stored XSS Vulnerability in Johnson Controls Metasys

A stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-34491) in Johnson Controls Metasys allows low-privileged users to execute arbitrary scripts in the context of other users' sessions, potentially leading to session hijacking.

Metasys industrial-control-systems xss web-vulnerability
1r 1t
high advisory

Johnson Controls Airwall Hard-coded Credentials and Path Traversal Vulnerabilities

Johnson Controls Airwall versions 4.0.4 and earlier are affected by CVE-2026-64887 and CVE-2026-34492, allowing attackers to potentially decrypt sensitive data or perform arbitrary file reads.

Airwall ics cve-2026-64887 cve-2026-34492
3t
critical advisory

Critical Vulnerabilities in Johnson Controls C-CURE 9000 and victor

Multiple vulnerabilities in Johnson Controls C-CURE 9000 and victor application servers, including .NET deserialization (CVE-2026-21655), allow unauthenticated remote code execution and unauthorized information disclosure.

C-CURE 9000 +3
1r 1t 3c
medium advisory

Hardcoded Credentials in Johnson Controls TL280

Johnson Controls TL280 devices running firmware versions below 5.63 contain hardcoded credentials and utilize insecure cryptographic algorithms, potentially allowing unauthorized access.

TL280 vulnerability ics iot