EXPOSURES › CVE-2026-21662
CVE-2026-21662
CRITICAL
DETAIL
SourceNVD · cve
Published2026-07-31
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-21662 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.