As cited
Copy frozen at (site build).
vulnerabilities
Johnson Controls C-CURE 9000 and Victor application server
Johnson Controls disclosed critical vulnerabilities in C-CURE 9000 and Victor application servers affecting versions C-CURE 9000/Victor through v2.90_v3.0 and Victor Web through v7.1. CVE-2026-21655 allows unauthenticated attackers on adjacent networks to achieve remote code execution through unsafe deserialization, while CVE-2026-21653 enables server-side request forgery attacks. The vendor recommends upgrading to version 3.20 or later and implementing network segmentation, firewall rules, intrusion detection, and application whitelisting.
Why it matters: Physical security teams and infrastructure operators running C-CURE 9000 or Victor systems worldwide face immediate remote code execution risk if systems are not patched to version 3.20 or later; urgent patching or network isolation of port 8999 is required to prevent compromise of physical security controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Johnson Controls C-CURE 9000 and Victor application server
Johnson Controls disclosed critical vulnerabilities in C-CURE 9000 and Victor application servers affecting versions C-CURE 9000/Victor through v2.90_v3.0 and Victor Web through v7.1. CVE-2026-21655 allows unauthenticated attackers on adjacent networks to achieve remote code execution through unsafe deserialization, while CVE-2026-21653 enables server-side request forgery attacks. The vendor recommends upgrading to version 3.20 or later and implementing network segmentation, firewall rules, intrusion detection, and application whitelisting.
Why it matters: Physical security teams and infrastructure operators running C-CURE 9000 or Victor systems worldwide face immediate remote code execution risk if systems are not patched to version 3.20 or later; urgent patching or network isolation of port 8999 is required to prevent compromise of physical security controls.
- Source published
- First seen by Cybersecurity Tracker