vulnerability Johnson Controls OpenBlue Employee Johnson Controls has released a security advisory (JCI-PSA-2026-09) addressing critical vulnerabilities in its OpenBlue Employee system. These vulnerabilities – including stored XSS, HTML injection, and file upload flaws – could allow attackers to execute malicious code, inject arbitrary HTML content, and potentially c… CISA Advisories · Jul 30, 2026 High CVE-2026-21662CVE-2026-34495CVE-2026-34497vulnerabilityxsshtml injection