VYPR
Vypr IntelligenceAI-generatedJul 23, 2026· 3 CVEs

Johnson Controls C-CURE 9000: Three Critical RCE, SSRF, and Auth Bypass Flaws Disclosed Together

Johnson Controls C-CURE 9000 and Victor application servers face three critical vulnerabilities, including RCE and SSRF, disclosed on July 23, 2026.

Key findings

  • Three critical vulnerabilities (CVSS up to 9.6) disclosed in Johnson Controls C-CURE 9000 and Victor application servers on July 23, 2026.
  • CVE-2026-21655 allows unauthenticated RCE from adjacent networks; CVE-2026-21653 enables SSRF attacks.
  • CVE-2026-34496 permits low-privilege users to access unauthorized pages and sensitive information.
  • Affected versions include C-CURE 9000/Victor <=v2.90_v3.0 and Victor Web <=v7.1. Patches are available.

On July 23, 2026, three critical vulnerabilities were disclosed in Johnson Controls' C-CURE 9000 and Victor application server systems. These vulnerabilities, carrying CVSS scores up to 9.6, could allow attackers to achieve remote code execution, access unauthorized data, and perform server-side request forgery attacks. The disclosures were consolidated by CISA in advisory ICSA-26-204-01.

Two of the vulnerabilities, CVE-2026-21655 (CVSS 8.8) and CVE-2026-21653 (CVSS 9.6), pose the most significant risk. CVE-2026-21655 could permit an unauthenticated attacker on an adjacent network to execute arbitrary code on the application server and connected clients. CVE-2026-21653, a critical server-side request forgery (SSRF) vulnerability, could enable an attacker to interact with internal services, potentially leading to further compromise.

A third vulnerability, CVE-2026-34496 (CVSS 8.0), allows low-privilege users to access unauthorized pages, such as user and log information, exposing sensitive system and user account details.

The affected versions include C-CURE 9000 and Victor versions up to and including v2.90_v3.0, and Victor Web versions up to and including v7.1. Johnson Controls has released patches to address these security flaws. Users are strongly advised to update their systems to the latest versions to mitigate the risks associated with these vulnerabilities.

The coordinated disclosure of these high-severity flaws highlights the ongoing threats to physical security systems. Successful exploitation could have far-reaching consequences, impacting critical infrastructure sectors like critical manufacturing, where these systems are deployed worldwide. Prompt patching and vigilance are essential for organizations relying on C-CURE 9000 and Victor for their security operations.

AI-written article. Grounded in 3 CVE records listed below.