CVE-2025-26383: Johnson Controls Istar Configuration Utility Icu
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.
Affected products
- Johnson Controls Istar Configuration Utility Icu
Published 2025-06-11. Last modified 2026-06-17.