Answer in brief
CVE-2026-21661 records a High severity (CVSS 8.4) vulnerability in AC2000 Uncontrolled Search Path Element. The current sources do not mark it as known exploited. The current feed maps Johnson Controls/AC2000 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Johnson Controls/AC2000 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Johnson Controls/AC2000generic | >=10.6 <release 10 || >=11.0 <release 9 || >=12 <release 3 | release 10, release 9, release 3, release |
Published upstream
May 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 24, 2026
An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.
Quoted source text, attributed separately from HOL analysis.