CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Johnson Controls C-CURE 9000 and Victor application server

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3120

As cited

Copy frozen at (site build).

vulnerabilities

Johnson Controls C-CURE 9000 and Victor application server

Johnson Controls disclosed critical vulnerabilities in C-CURE 9000 and Victor application servers affecting versions C-CURE 9000/Victor through v2.90_v3.0 and Victor Web through v7.1. CVE-2026-21655 allows unauthenticated attackers on adjacent networks to achieve remote code execution through unsafe deserialization, while CVE-2026-21653 enables server-side request forgery attacks. The vendor recommends upgrading to version 3.20 or later and implementing network segmentation, firewall rules, intrusion detection, and application whitelisting.

Why it matters: Physical security teams and infrastructure operators running C-CURE 9000 or Victor systems worldwide face immediate remote code execution risk if systems are not patched to version 3.20 or later; urgent patching or network isolation of port 8999 is required to prevent compromise of physical security controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Johnson Controls C-CURE 9000 and Victor application server

Johnson Controls disclosed critical vulnerabilities in C-CURE 9000 and Victor application servers affecting versions C-CURE 9000/Victor through v2.90_v3.0 and Victor Web through v7.1. CVE-2026-21655 allows unauthenticated attackers on adjacent networks to achieve remote code execution through unsafe deserialization, while CVE-2026-21653 enables server-side request forgery attacks. The vendor recommends upgrading to version 3.20 or later and implementing network segmentation, firewall rules, intrusion detection, and application whitelisting.

Why it matters: Physical security teams and infrastructure operators running C-CURE 9000 or Victor systems worldwide face immediate remote code execution risk if systems are not patched to version 3.20 or later; urgent patching or network isolation of port 8999 is required to prevent compromise of physical security controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary