Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · johnsoncontrols

johnsoncontrols

· 13 Critical

Total CVEs

68

Critical

13

Products

113

Search All CVEs →

68

Products (113)

metasys extended application and data server11 CVEsmetasys application and data server10 CVEsmetasys open application server10 CVEsexacqvision web service8 CVEsfrick controls quantum hd firmware6 CVEsfrick controls quantum hd6 CVEsmetasys system configuration tool4 CVEsexacqvision server4 CVEsc-cure 9000 firmware3 CVEsmetasys system3 CVEsnetwork automation engine 5521-22 CVEsf4-snc firmware2 CVEsnetwork integration engine 5510-22 CVEsnetwork integration engine 5511-22 CVEsc-cure 90002 CVEskantech entrapass2 CVEsapplication and data server2 CVEslonworks control server lcs85202 CVEsnxe85002 CVEsopenblue enterprise manager data collector2 CVEsexacqvision enterprise manager2 CVEsextended application and data server2 CVEsf4-snc2 CVEsvideoedge2 CVEsmetsys2 CVEsnae552 CVEsnae55 firmware2 CVEsistar ultra2 CVEsistar ultra firmware2 CVEsnetwork automation engine 5510-22 CVEsnetwork automation engine 5510-2u2 CVEsnetwork automation engine 5511-22 CVEsnetwork automation engine 5520-22 CVEsnie551 CVEsnie55 firmware1 CVEsnie591 CVEsnie59 firmware1 CVEsnie851 CVEsnie85 firmware1 CVEsord-c100-13 uuklc1 CVEsord-c100-13 uuklc firmware1 CVEspegasys p2000 server1 CVEspegasys p2000 server software1 CVEsqolsys iq4 hub1 CVEsqolsys iq4 hub firmware1 CVEsqolsys iq panel 41 CVEsqolsys iq panel 4 firmware1 CVEsquantum hd unity acuair1 CVEsquantum hd unity acuair firmware1 CVEsquantum hd unity compressor1 CVEsquantum hd unity compressor firmware1 CVEsquantum hd unity condenser\/vessel1 CVEsquantum hd unity condenser\/vessel firmware1 CVEsquantum hd unity engine room1 CVEsquantum hd unity engine room firmware1 CVEsquantum hd unity evaporator1 CVEsquantum hd unity evaporator firmware1 CVEsquantum hd unity interface1 CVEsquantum hd unity interface firmware1 CVEssnc16120-01 CVEssnc16120-041 CVEssnc16120-04 firmware1 CVEssnc16120-0 firmware1 CVEssnc25150-01 CVEssnc25150-041 CVEssnc25150-04 firmware1 CVEsac20001 CVEssne105001 CVEssne10500 firmware1 CVEssne110001 CVEssne11000 firmware1 CVEssne110l01 CVEssne110l0 firmware1 CVEssne220001 CVEssne22000 firmware1 CVEssoftware house c-cure 9000 siteserver1 CVEsul 864 uukl1 CVEsul 864 uukl firmware1 CVEsvictor web1 CVEsvictor web client1 CVEssnc25150-0 firmware1 CVEsac2000 firmware1 CVEsbcpro1 CVEsc-cure web1 CVEscevas1 CVEseasyio cpt graphics1 CVEsedge g21 CVEsedge g2 firmware1 CVEsentrapass1 CVEsexacqvision client1 CVEsillustra pro gen 4 dome1 CVEsillustra pro gen 4 dome firmware1 CVEsillustra pro gen 4 ptz1 CVEsillustra pro gen 4 ptz firmware1 CVEsiosmart gen 11 CVEsiosmart gen 1 firmware1 CVEsiq wifi 61 CVEsiq wifi 6 firmware1 CVEsistar ultra g21 CVEsistar ultra g2 firmware1 CVEsistar ultra lt1 CVEsistar ultra lt firmware1 CVEskantech kt-1 door controller1 CVEskantech kt-1 door controller firmware1 CVEsmetasys1 CVEsmetasys for validated environments1 CVEsmetasys lonworks control server1 CVEsmetasys open data server1 CVEsmetasys reporting engine1 CVEsnae851 CVEsnae85 firmware1 CVEsnetwork controller1 CVEsnetwork controller firmware1 CVEs

Recent Vulnerabilities

View all 68
CVE-2026-21660CRITICAL 9.8

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVE-2026-21659CRITICAL 9.8

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Frick Controls Quantum HD: Frick Controls Quantum HD version 10.22 and prior.

CVE-2026-21658CRITICAL 9.8

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVE-2026-21657CRITICAL 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVE-2026-21656CRITICAL 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVE-2026-21654CRITICAL 9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVE-2024-32931MEDIUM 5.7

Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

CVE-2024-32865MEDIUM 6.4

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

CVE-2024-32862MEDIUM 6.8

Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

CVE-2024-32758HIGH 7.5

Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange

CVE-2024-32864MEDIUM 6.4

Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

CVE-2024-32863MEDIUM 6.8

Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

CVE-2024-0912MEDIUM 4.2

Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

CVE-2024-0242HIGH 7.3

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

CVE-2023-0248HIGH 7.5

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.

CVE-2023-4486HIGH 7.5

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

CVE-2023-4804CRITICAL 10.0

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

CVE-2023-3749HIGH 7.1

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

CVE-2023-3548HIGH 8.3

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

CVE-2023-3127HIGH 7.5

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

CVE-2023-0954HIGH 8.3

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

CVE-2023-2025MEDIUM 5.0

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

CVE-2023-2024CRITICAL 10.0

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

CVE-2022-21940HIGH 7.5

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

CVE-2022-21939HIGH 7.5

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.