CVE-2025-26383: Johnson Controls Istar Configuration Utility Icu

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.

Affected products

Published 2025-06-11. Last modified 2026-06-17.