High severityNVD Advisory· Published Jul 23, 2026· Updated Aug 6, 2026
CVE-2026-21655
CVE-2026-21655
Description
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.
This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: from 2.9 before 3.0
Patches
Vulnerability mechanics
References
1News mentions
2- Johnson Controls C-CURE 9000: Three Critical RCE, SSRF, and Auth Bypass Flaws Disclosed TogetherVypr Intelligence · Jul 23, 2026
- Johnson Controls C-CURE 9000 and Victor application server (Update A)CISA ICS Advisories