← Back to Feed
Johnson Controls C-CURE 9000 and Victor application server
CVE-2026-21655
July 23, 2026 · CISA (US-CERT) · Severity: CRITICAL
CISA published an advisory on vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server used for physical access control. Exploitation could lead to authentication bypass and system compromise. Users should apply vendor patches and implement network segmentation for these OT systems.
Key Takeaways
- View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to.
- The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected: C-CURE 9000 and. View CVE Details Affected Products Johnson Controls C-CURE 9000 and Victor application server Vendor:Johnson.