ā Back to Feed
Johnson Controls C-CURE 9000 and Victor application server (Update A)
CVE-2026-21655CVE-2026-34496
August 11, 2026 Ā· CISA (US-CERT) Ā· Severity: CRITICAL
Multiple critical vulnerabilities in Johnson Controls' C-CURE 9000 and Victor application server (Update A) could allow unauthenticated attackers on an adjacent network to execute arbitrary code. Successful exploitation may impact physical security systems, posing significant risks to critical manufacturing infrastructure. The flaws affect specific versions of C-CURE 9000, Victor Application Server, and Victor Web, requiring urgent patching. š **Analyst Note:** Organizations using affected versions should prioritize upgrades, as these vulnerabilities could bridge cyber-physical security gaps.
Key Takeaways
- Critical vulnerabilities in Johnson Controls C-CURE 9000 and Victor servers allow remote code execution.
- Attackers can exploit these flaws to compromise physical security controls via adjacent network access.
- Affected versions include C-CURE 9000 ā¤v3.10.1 and Victor Application Server ā¤v4.10, among others.
- Johnson Controls recommends immediate upgrades to patched versions to mitigate exploitation risks.