PatchSiren cyber security CVE debrief
CVE-2026-21653 Johnson Controls CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:00:00.000Z and has not been modified since then. This critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application, potentially leading to unauthorized information disclosure or lateral movement within the network. Organizations should prioritize patching to prevent potential unauthorized access and lateral movement. The vulnerability has a CVSS score of 9.6 and is considered critical.
- Vendor
- Johnson Controls
- Product
- C-CURE 9000 and victor
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-07-23
Who should care
Organizations using Johnson Controls C-CURE 9000 and Victor application server, particularly those in industrial control systems environments, should prioritize patching this vulnerability to prevent potential unauthorized access and lateral movement within their networks.
Technical summary
The vulnerability in Johnson Controls C-CURE 9000 and Victor application server allows an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. The vulnerability has a CVSS score of 9.6 and is considered critical. Successful exploitation could allow an attacker to interact with internal services, potentially leading to unauthorized information disclosure or lateral movement within the network.
Defensive priority
Critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server, allowing for potential unauthorized information disclosure or lateral movement within the network.
Recommended defensive actions
- Update all victor Web installations to version 7.0 or later
- Implement strict firewall rules to block unnecessary inbound connections to port 8999
- Deploy IDS/IPS signatures to detect known .NET deserialization exploit payloads
- Enforce application whitelisting on application server hosts
- Ensure the application server process runs with minimum privileges
- Enable detailed logging and monitor for anomalous process creation
Evidence notes
Evidence from CISA CSAF and CVE.org indicates a critical vulnerability in Johnson Controls C-CURE 9000 and Victor application server. The vulnerability allows an attacker to forge server-side HTTP requests, potentially leading to unauthorized information disclosure or lateral movement. Johnson Controls has provided a fix in version 7.0 or later of victor Web.
Official resources
-
CVE-2026-21653 CVE record
CVE.org
-
CVE-2026-21653 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:00:00.000Z and has not been modified since then.