CVE-2025-26382: Johnson Controls Istar Configuration Utility Icu
Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
Affected products
- Johnson Controls Istar Configuration Utility Icu: before 6.9.5 (fixed in 6.9.5)
Published 2025-04-24. Last modified 2026-06-17.