Critical SQL Injection Vulnerability in Johnson Controls ICS Products
First seen 1 Feb 2026, 22:57 UTC
•
•59
Export
Article Content
Browse articles
CISA issued a critical alert regarding a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, has a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk. It arises from improper neutralization of special elements used in command injection, allowing remote exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.