CVE-2026-21661: Johnson Controls AC2000

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.

Affected products

  • Johnson Controls AC2000: from 10.6, before 10 (fixed in 10); from 11.0, before 9 (fixed in 9); from 12, before 3 (fixed in 3)

Published 2026-05-06. Last modified 2026-08-24.