THREATOPS
THREAT OPSThreat News › Johnson Controls Metasys

Johnson Controls Metasys

medcisa_icsPublished 2026-08-13

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-225-14.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, pot

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14

Same event, other sources