CISA published an ICS advisory warning that Johnson Controls Frick Controls Quantum HD (versions 10.22 and earlier) contains multiple vulnerabilities that can be exploited before authentication, enabling remote code execution (RCE), information leakage, and potentially denial of service in environments where the product is deployed (noted as worldwide, including Food and Agriculture critical infrastructure). CISA lists a CVSS v3.1 base score of 9.1 (Critical) for the issue set and attributes the root cause across several items to insufficient input validation in device parameters.
The disclosed CVEs include CVE-2026-21654 (OS command injection, CWE-78) and several code injection RCE issues (CVE-2026-21656, CVE-2026-21657, CVE-2026-21658, CWE-94) that could allow unexpected actions and system compromise without credentials. CVE-2026-21659 describes local file inclusion (LFI) (CWE-23) leading to unauthenticated RCE and information disclosure, explicitly stating an attacker could execute arbitrary code and achieve full system compromise on affected devices. The advisory also references an additional CVE (CVE-2026-21660) not detailed in the other provided entries, indicating the exposure spans more than the five CVE records included here.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A vulnerability tracked as CVE-2026-32817 affecting Admidio versions 5.0.0 through 5.0.6 was disclosed as fixed in version 5.0.7. The flaw allowed unauthorized deletion of files and folders, including unauthenticated deletion in some public-mode configurations.
Multiple CVE records for Johnson Controls Frick Controls Quantum HD vulnerabilities, including CVE-2026-21654, CVE-2026-21656, CVE-2026-21657, CVE-2026-21658, and CVE-2026-21659, were received or modified by productsecurity@jci.com and enriched with CVSS v4 scoring, CWE mappings, and references to CISA and Johnson Controls advisories. The updates covered unauthenticated remote code execution and information disclosure issues affecting version 10.22 and earlier.
CISA published ICS advisory ICSA-26-057-01 describing multiple vulnerabilities in Johnson Controls Frick Controls Quantum HD 10.22 and earlier, including OS command injection, code injection, path traversal, plaintext password storage, and hardcoded credentials. CISA said the flaws could enable pre-authentication remote code execution, information disclosure, or denial of service and noted no known public exploitation as of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.