PatchSiren cyber security CVE debrief
CVE-2026-21653 Johnson Controls CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:00:00.000Z and has not been modified since then. This critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application, potentially leading to unauthorized information disclosure or lateral movement within the network. Organizations should prioritize patching to prevent potential unauthorized access and lateral movement. The vulnerability has a CVSS score of 9.6 and is considered critical.
- Vendor
- Johnson Controls
- Product
- C-CURE 9000 and victor
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-07-23
Who should care
Organizations using Johnson Controls C-CURE 9000 and Victor application server, particularly those in industrial control systems environments, should prioritize patching this vulnerability to prevent potential unauthorized access and lateral movement within their networks.
Technical summary
The vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. The vulnerability has a CVSS score of 9.6 and is considered critical. Successful exploitation could allow an attacker to interact with internal services, potentially leading to unauthorized information disclosure or lateral movement within the network.
Defensive priority
Critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server, allowing for potential unauthorized information disclosure or lateral movement within the network.
Recommended defensive actions
- Update all victor Web installations to version 7.0 or later
- Implement strict firewall rules to block unnecessary inbound connections to port 8999
- Deploy IDS/IPS signatures to detect known .NET deserialization exploit payloads
- Enforce application whitelisting on application server hosts
- Ensure the application server process runs with minimum privileges
- Enable detailed logging and monitor for anomalous process creation
Evidence notes
Evidence from CISA CSAF and CVE.org indicates a critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server. The vulnerability allows an attacker to forge server-side HTTP requests, potentially leading to unauthorized information disclosure or lateral movement. Johnson Controls has provided a fix in version 7.0 or later of victor Web.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-21653 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-21653
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-21653 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21653
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-204-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.