Connect with us

Security

Cybersecurity Alert: Vulnerability Detected in Johnson Controls Metasys Systems

Published

on

Discovering a Critical Vulnerability in Building Automation System

An alarming weakness in Johnson Controls’ Metasys building automation technology has been uncovered in an industrial security alert (ICSA-26-225-14) issued by CISA on August 13, 2026. This vulnerability, identified as CVE-2026-34491, allows a low-privilege, authorized attacker to inject malicious code into the Metasys interface through a customized URL. The injected code operates discreetly, persisting throughout user sessions, potentially leading to session hijacking, complete account takeovers, and unauthorized control over building operations.

Impacted Versions and Recommended Security Measures

Metasys versions 12 to 15, commonly utilized in managing facilities such as hospitals, airports, data centers, and commercial real estate, are susceptible to this issue. CISA urgently advises facility management and security teams to address this vulnerability promptly. A fix has been implemented in Metasys version 16.0, with specific patches available for earlier supported releases. In addition to applying updates, it is crucial to secure building automation networks behind robust firewalls, keep these systems offline from the public internet, and utilize secure VPNs for remote administrative access.

Author Notes
CISA Advisory ICSA-26-225-14: Johnson Controls Metasys (Published August 13, 2026).

Carmen Estela serves as a Cybersecurity Research Analyst at Cyber Defense Magazine and is a nominee for the Women in Cybersecurity Award. She recently obtained a Master of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida, along with certifications in Data Analytics and AI Fundamentals. Carmen actively participates in renowned industry events like BSides Orlando and BSides Jax, sharing insights on emerging cyber trends. With a dedication to enhancing cybersecurity governance, risk, and compliance standards, she has experience in various investigative roles in law enforcement, academia, and public service.

See also  Code Vulnerability Alert: GitHub Tokens Easily Compromised in VS Code Security Flaw

Connect with Carmen via email at [email protected].

 

Trending