High severityNVD Advisory· Published Jul 23, 2026· Updated Jul 30, 2026
CVE-2026-34496
CVE-2026-34496
Description
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.
This issue affects victor Web: before 7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <7.1
Patches
Vulnerability mechanics
References
1News mentions
2- Johnson Controls C-CURE 9000: Three Critical RCE, SSRF, and Auth Bypass Flaws Disclosed TogetherVypr Intelligence · Jul 23, 2026
- Johnson Controls C-CURE 9000 and Victor application server (Update A)CISA ICS Advisories