Critical Vulnerabilities Discovered in Johnson Controls C-CURE 9000 and Victor Application Server
CISA and Johnson Controls have issued advisories regarding multiple critical vulnerabilities affecting C-CURE 9000 and Victor application server products. The vulnerabilities, primarily tracked as CVE-2026-21655, CVE-2026-34496, and CVE-2026-21653, involve server-side request forgery (SSRF) that could allow unauthenticated remote attackers to achieve arbitrary code execution, impact physical security controls, and facilitate lateral movement within networks. Affected versions span C-CURE 9000 up to v3.10.1, victor Application Server up to v4.10, victor up to v7.0, and victor Web up to v7.1. Johnson Controls has released vendor fixes recommending upgrades to newer versions to address the vulnerable deserialization paths.