CISA 2026-07-23 Johnson Controls XAAP Android CVE-2026-34490 From Cybersecurity and Infrastructure Security Agency ↗ Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android Read the full advisory on CISA →