CISA Warns: Johnson Controls C-CURE 9000 Security Platform Under Active Exploitation (CVE-2026-21655)
Johnson Controls' C-CURE 9000 and Victor application server platforms — which manage access control, video surveillance, and physical security across thousands of commercial and industrial facilities worldwide — have been hit with a CISA advisory (ICSA-26-204-01) identifying a critical vulnerability that allows unauthenticated remote code execution on adjacent networks.
CVE-2026-21655 is a deserialization of untrusted data flaw in the Victor application (affecting versions up to v2.90/v3.0) on Windows. Under certain conditions, an attacker on the same network segment can exploit a vulnerable deserialization path (LV1.1) to execute arbitrary code on the C-CURE 9000 or Victor server, as well as on connected workstations used by physical security personnel. The vulnerability carries a CVSS v3 score of 9.6 — classified as Critical — and has already been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.
A companion vulnerability, CVE-2026-21653, is a Server-Side Request Forgery (SSRF) flaw in the Victor web component (versions up to v7.1) that enables a high-privilege attacker to cause the server to initiate unexpected network connections to internal resources. OffSeq's Threat Radar analysis notes the CVSS 4.0 vector shows a network attack path with low complexity, partial privileges required, and high impact on confidentiality and integrity.

Johnson Controls has released a fix in C-CURE 9000 / Victor version 3.20 and later. Until organizations upgrade, the vendor recommends network segmentation: isolate C-CURE 9000 and Victor application servers on a dedicated segment and restrict access to port 8999 to only authorized systems.
For
Sources
Comments
Post a Comment