High severityNVD Advisory· Published Jul 23, 2026· Updated Jul 30, 2026
CVE-2026-21653
CVE-2026-21653
Description
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 2.9 - 3.0
- Range: 2.9 - 3.0
Patches
Vulnerability mechanics
References
1News mentions
2- Johnson Controls C-CURE 9000: Three Critical RCE, SSRF, and Auth Bypass Flaws Disclosed TogetherVypr Intelligence · Jul 23, 2026
- Johnson Controls C-CURE 9000 and Victor application server (Update A)CISA ICS Advisories