Multiple security vulnerabilities affecting C-CURE 9000 and victor application servers versions C-CURE 9000 and victor up to v2 have been identified in Johnson Controls C-CURE 9000 and victor application servers. The most severe vulnerability.
CVE-2026-21653 (CVSS 7.2 — High): The victor Web application can be tricked into sending requests on the attacker’s behalf, enabling information disclosure and lateral movement due to a server-side request forgery issue tracked as CWE-918. These vulnerabilities collectively present a significant risk to large facilities relying on C-CURE 9000 for door controls, badge readers, and alarm logic. Administrators should update C-CURE 9000 and victor to version 3.20 or later and restrict port 8999 to authorized systems only.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting C-CURE 9000 and victor application servers versions C-CURE 9000 and victor up to v2 have been identified in Johnson Controls C-CURE 9000 and victor application servers. The most severe vulnerability.
CVE-2026-21653 (CVSS 7.2 — High): The victor Web application can be tricked into sending requests on the attacker’s behalf, enabling information disclosure and lateral movement due to a server-side request forgery issue tracked as CWE-918. These vulnerabilities collectively present a significant risk to large facilities relying on C-CURE 9000 for door controls, badge readers, and alarm logic. Administrators should update C-CURE 9000 and victor to version 3.20 or later and restrict port 8999 to authorized systems only.[emaillocker id="1283"]
CVE-2026-21655 (CVSS 8.7 — Critical): An unauthenticated attacker on the adjacent network gains arbitrary code execution on the application server and connected clients by abusing a deserialization path reachable over port 8999.
CVE-2026-34496 (CVSS 7.1 — High): Privilege Escalation occurs in Low-privilege users can open restricted pages such as Users and Logs exposing account details and audit records beyond their intended access level.
Mitigating these critical risks demands a comprehensive approach focused on immediate software remediation and rigorous network hardening. Administrators must upgrade all vulnerable server components and web applications to the latest vendor-secured versions. Network infrastructure should be isolated using dedicated segments, restricting vulnerable service ports exclusively to trusted administrative systems. Additionally, security teams should monitor process execution anomalies, enforce strict least-privilege principles, and disable unnecessary callback interfaces to ensure robust defensive posture.
The following reports contain further technical details:
[/emaillocker]