Critical Vulnerabilities in Johnson Controls C-CURE 9000 and Victor Applications Allow Remote Code Execution
CISA has issued an advisory detailing two critical vulnerabilities in Johnson Controls' C-CURE 9000 and Victor application servers, potentially enabling unauthenticated attackers to achieve arbitrary code execution and forge server-side requests.

CISA has released an advisory highlighting two severe vulnerabilities affecting Johnson Controls' C-CURE 9000 and Victor application server software, which are widely used for physical security management in critical infrastructure.
One of the vulnerabilities, identified as CVE-2026-21655, allows an unauthenticated attacker with adjacent network access to execute arbitrary code on the C-CURE 9000 or Victor application server. This could also extend to connected client workstations used by physical security personnel, potentially leading to a complete compromise of physical security controls.
The second vulnerability, CVE-2026-21653, impacts the Victor Web application. It enables an attacker to forge server-side HTTP requests, which could be exploited to interact with internal services on the host or other network-accessible systems. This could result in unauthorized information disclosure or facilitate lateral movement within the compromised network.
Affected versions include C-CURE 9000 and Victor application servers running versions up to and including v2.90_v3.0, and the Victor Web application up to version v7.1. The vulnerabilities carry high CVSS scores, with CVE-2026-21655 rated at 8.8 (HIGH) and CVE-2026-21653 rated at 9.6 (CRITICAL).
Johnson Controls has provided specific remediation guidance. For CVE-2026-21655, users are advised to upgrade to C-CURE 9000 / Victor version 3.20 or later. For CVE-2026-21653, updating Victor Web installations to version 7.0 or later is recommended.
In addition to vendor-provided fixes, CISA and Johnson Controls recommend several mitigation strategies. These include network segmentation to isolate the affected servers, implementing strict firewall rules to restrict access to port 8999, and deploying intrusion detection/prevention systems tuned to detect .NET deserialization exploit payloads. Application whitelisting, enforcing least privilege for the application server process, and enabling detailed logging for monitoring anomalous activity are also advised.
Further mitigation steps involve disabling unnecessary services, particularly the ClientConnectionManager_NF.SynchronousServerNotification callback interface if not required, to reduce the attack surface. Detailed instructions for these mitigations can be found in Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16.
The exploitation of these vulnerabilities could have significant consequences for organizations relying on these systems for physical security, potentially leading to unauthorized access, data breaches, and disruption of critical operations. The advisory emphasizes the importance of timely patching and implementing robust security practices to protect these sensitive systems.