CISA Warns: Johnson Controls C-CURE 9000 Security Platform Under Active Exploitation (CVE-2026-21655)

Johnson Controls' C-CURE 9000 and Victor application server platforms — which manage access control, video surveillance, and physical security across thousands of commercial and industrial facilities worldwide — have been hit with a CISA advisory (ICSA-26-204-01) identifying a critical vulnerability that allows unauthenticated remote code execution on adjacent networks.

CVE-2026-21655 is a deserialization of untrusted data flaw in the Victor application (affecting versions up to v2.90/v3.0) on Windows. Under certain conditions, an attacker on the same network segment can exploit a vulnerable deserialization path (LV1.1) to execute arbitrary code on the C-CURE 9000 or Victor server, as well as on connected workstations used by physical security personnel. The vulnerability carries a CVSS v3 score of 9.6 — classified as Critical — and has already been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.

A companion vulnerability, CVE-2026-21653, is a Server-Side Request Forgery (SSRF) flaw in the Victor web component (versions up to v7.1) that enables a high-privilege attacker to cause the server to initiate unexpected network connections to internal resources. OffSeq's Threat Radar analysis notes the CVSS 4.0 vector shows a network attack path with low complexity, partial privileges required, and high impact on confidentiality and integrity.

U.S. flag
Source image 1

Johnson Controls has released a fix in C-CURE 9000 / Victor version 3.20 and later. Until organizations upgrade, the vendor recommends network segmentation: isolate C-CURE 9000 and Victor application servers on a dedicated segment and restrict access to port 8999 to only authorized systems.

For

Source article image
Source image 2
building management and physical security teams, this is a high-priority patch. C-CURE 9000 and Victor are deployed across airports, data centers, government facilities, and manufacturing plants — making the RCE path especially dangerous for organizations that rely on these platforms for both digital and physical perimeter defense.

Sources

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door