CVE-2025-43876: Johnson Controls Istar Ultra, Istar Ultra SE
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Under certain circumstances a successful exploitation could result in access to the device.
Affected products
- Johnson Controls Istar Ultra, Istar Ultra SE: up to and including 6.9.7
- Johnson Controls Istar Ultra g2, Istar Ultra g2 Se, Istar Edge g2: up to and including 6.9.2
Published 2025-12-24. Last modified 2026-10-07.