Threat Advisory

C-CURE 9000 and victor Application Server Flaws Grant Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting C-CURE 9000 and victor application servers versions C-CURE 9000 and victor up to v2 have been identified in Johnson Controls C-CURE 9000 and victor application servers. The most severe vulnerability.

CVE-2026-21653 (CVSS 7.2 — High): The victor Web application can be tricked into sending requests on the attacker’s behalf, enabling information disclosure and lateral movement due to a server-side request forgery issue tracked as CWE-918. These vulnerabilities collectively present a significant risk to large facilities relying on C-CURE 9000 for door controls, badge readers, and alarm logic. Administrators should update C-CURE 9000 and victor to version 3.20 or later and restrict port 8999 to authorized systems only.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting C-CURE 9000 and victor application servers versions C-CURE 9000 and victor up to v2 have been identified in Johnson Controls C-CURE 9000 and victor application servers. The most severe vulnerability.

CVE-2026-21653 (CVSS 7.2 — High): The victor Web application can be tricked into sending requests on the attacker’s behalf, enabling information disclosure and lateral movement due to a server-side request forgery issue tracked as CWE-918. These vulnerabilities collectively present a significant risk to large facilities relying on C-CURE 9000 for door controls, badge readers, and alarm logic. Administrators should update C-CURE 9000 and victor to version 3.20 or later and restrict port 8999 to authorized systems only.[emaillocker id="1283"]

CVE-2026-21655 (CVSS 8.7 — Critical): An unauthenticated attacker on the adjacent network gains arbitrary code execution on the application server and connected clients by abusing a deserialization path reachable over port 8999.

CVE-2026-34496 (CVSS 7.1 — High): Privilege Escalation occurs in Low-privilege users can open restricted pages such as Users and Logs exposing account details and audit records beyond their intended access level.

Mitigating these critical risks demands a comprehensive approach focused on immediate software remediation and rigorous network hardening. Administrators must upgrade all vulnerable server components and web applications to the latest vendor-secured versions. Network infrastructure should be isolated using dedicated segments, restricting vulnerable service ports exclusively to trusted administrative systems. Additionally, security teams should monitor process execution anomalies, enforce strict least-privilege principles, and disable unnecessary callback interfaces to ensure robust defensive posture.

RECOMMENDATIONS:

  • We recommend you to update Johnson Controls C-CURE 9000 and victor application server to version 3.20 or later.
  • We recommend you to update victor Web installations to version 7.0 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu