VYPR

Victor application server

by Johnson Controls

CVEs (3)

  • CVE-2026-21653criJul 23, 2026
    risk 0.62cvss 9.6epss

    Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local…

  • CVE-2026-21655higJul 23, 2026
    risk 0.57cvss 8.8epss

    Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of…

  • CVE-2026-34496higJul 23, 2026
    risk 0.52cvss 8.0epss

    Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and…