Johnson Controls C-CURE 9000 and Victor application server
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. /strong /p p The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected: /p ul li C-CURE 9000 and victor lt;=v2.90_v3.0 nbsp; /li li victor Web lt;=v7.1 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 9.6 /td td Johnson Controls /td td Johnson Controls C-CURE 9000 and Victor application server /td td Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Ireland /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-21655 /a /h3 div class= csaf-accordion-content p Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of physical security personnel). Such an attack could impact physical security controls. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-21655 View CVE Details /a /p hr h4 Affected Products /h4 h5 Johnson Controls C-CURE 9000 and Victor application server /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Johnson Controls /div div class= ics-version strong Product Version: /strong br Johnson Controls C-CURE 9000 and victor: lt;=v2.90_v3.0 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Mitigation /strong br Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1). /p p strong Vendor fix /strong br Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity. /p p strong Mitigation /strong br Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound c
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.