PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21653 Johnson Controls CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:00:00.000Z and has not been modified since then. This critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application, potentially leading to unauthorized information disclosure or lateral movement within the network. Organizations should prioritize patching to prevent potential unauthorized access and lateral movement. The vulnerability has a CVSS score of 9.6 and is considered critical.

Vendor
Johnson Controls
Product
C-CURE 9000 and victor
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-23
Advisory published
2026-07-23
Advisory updated
2026-07-23

Who should care

Organizations using Johnson Controls C-CURE 9000 and Victor application server, particularly those in industrial control systems environments, should prioritize patching this vulnerability to prevent potential unauthorized access and lateral movement within their networks.

Technical summary

The vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. The vulnerability has a CVSS score of 9.6 and is considered critical. Successful exploitation could allow an attacker to interact with internal services, potentially leading to unauthorized information disclosure or lateral movement within the network.

Defensive priority

Critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server, allowing for potential unauthorized information disclosure or lateral movement within the network.

Recommended defensive actions

  • Update all victor Web installations to version 7.0 or later
  • Implement strict firewall rules to block unnecessary inbound connections to port 8999
  • Deploy IDS/IPS signatures to detect known .NET deserialization exploit payloads
  • Enforce application whitelisting on application server hosts
  • Ensure the application server process runs with minimum privileges
  • Enable detailed logging and monitor for anomalous process creation

Evidence notes

Evidence from CISA CSAF and CVE.org indicates a critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server. The vulnerability allows an attacker to forge server-side HTTP requests, potentially leading to unauthorized information disclosure or lateral movement. Johnson Controls has provided a fix in version 7.0 or later of victor Web.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:00:00.000Z and has not been modified since then.