CISA Warns: Johnson Controls C-CURE 9000 Security Platform Under Active Exploitation (CVE-2026-21655)
Johnson Controls' C-CURE 9000 and Victor application server platforms — which manage access control, video surveillance, and physical security across thousands of commercial and industrial facilities worldwide — have been hit with a CISA advisory (ICSA-26-204-01) identifying a critical vulnerability that allows unauthenticated remote code execution on adjacent networks. CVE-2026-21655 is a deserialization of untrusted data flaw in the Victor application (affecting versions up to v2.90/v3.0) on Windows. Under certain conditions, an attacker on the same network segment can exploit a vulnerable deserialization path (LV1.1) to execute arbitrary code on the C-CURE 9000 or Victor server, as well as on connected workstations used by physical security personnel. The vulnerability carries a CVSS v3 score of 9.6 — classified as Critical — and has already been added to CISA's Known Exploited Vulnerabilities (KEV) catalog , confirming active exploitation in the wild. A companion vul...