PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21653 Johnson Controls CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:00:00.000Z and has not been modified since then. This critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application, potentially leading to unauthorized information disclosure or lateral movement within the network. Organizations should prioritize patching to prevent potential unauthorized access and lateral movement. The vulnerability has a CVSS score of 9.6 and is considered critical.

Vendor
Johnson Controls
Product
C-CURE 9000 and victor
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-23
Advisory published
2026-07-23
Advisory updated
2026-07-23

Who should care

Organizations using Johnson Controls C-CURE 9000 and Victor application server, particularly those in industrial control systems environments, should prioritize patching this vulnerability to prevent potential unauthorized access and lateral movement within their networks.

Technical summary

The vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. The vulnerability has a CVSS score of 9.6 and is considered critical. Successful exploitation could allow an attacker to interact with internal services, potentially leading to unauthorized information disclosure or lateral movement within the network.

Defensive priority

Critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server, allowing for potential unauthorized information disclosure or lateral movement within the network.

Recommended defensive actions

  • Update all victor Web installations to version 7.0 or later
  • Implement strict firewall rules to block unnecessary inbound connections to port 8999
  • Deploy IDS/IPS signatures to detect known .NET deserialization exploit payloads
  • Enforce application whitelisting on application server hosts
  • Ensure the application server process runs with minimum privileges
  • Enable detailed logging and monitor for anomalous process creation

Evidence notes

Evidence from CISA CSAF and CVE.org indicates a critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server. The vulnerability allows an attacker to forge server-side HTTP requests, potentially leading to unauthorized information disclosure or lateral movement. Johnson Controls has provided a fix in version 7.0 or later of victor Web.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-21653 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-21653

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-21653 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21653

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.