2026-08-28 · view entry permalink →
Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)
CISA's ICSA-26-204-01 (Update A, released 2026-08-11, tracking an initial release of 2026-07-23) covers three CVEs in Johnson Controls' physical access-control platform. CVE-2026-21655 (CVSS 3.1: 9.6 Critical, AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CVSS 4.0: 9.4) affects C-CURE 9000 ≤v3.10.1, victor Application Server ≤v4.10, and victor ≤v7.0. Per Johnson Controls' own remediation text, exploitation of "the vulnerable deserialization path" by an unauthenticated, adjacent-network attacker can achieve arbitrary code execution — and the blast radius extends past the server itself: "successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls" (CISA / Johnson Controls, ICSA-26-204-01, 2026-08-11). Fixed by upgrading to C-CURE 9000 v3.20+ / victor Application Server v4.20+ / victor v8.0+.
CVE-2026-21653 (same 9.6/9.4 CVSS) affects victor Web <v7.0 and lets an attacker forge server-side HTTP requests to reach internal services. CVE-2026-34496 (8.0/8.7, CWE-250 Execution with Unnecessary Privileges) affects victor Web ≤v7.1 and lets low-privilege users reach unauthorized admin pages (Users, Logs). No known public exploitation is reported for any of the three. Mitigations Johnson Controls names: isolate C-CURE 9000/victor application servers on a dedicated network segment, and restrict access to TCP/8999 to authorized systems only.
Worth flagging rather than silently resolving: CISA's own structured advisory data tags both CVE-2026-21655 and CVE-2026-21653 with CWE-918 (Server-Side Request Forgery), even though CVE-2026-21655's own summary and remediation both describe it as reaching code execution through a deserialization path — a CWE-502-class mechanism under a CWE-918 label. This is CISA's own document disagreeing with itself rather than a summarisation error introduced downstream, and it means a triage process filtering advisories by CWE class alone could misclassify this flaw's actual mechanism.
Physical access-control systems sit at the boundary between IT and physical security across government and critical-infrastructure facilities, so an unauthenticated code-execution path that names "connected clients" as reachable — explicitly including the workstations physical-security staff use — is a case where a network intrusion has a stated potential to become a physical-security failure. Triage: the detection anchor is unexpected inbound connections to TCP/8999 on any C-CURE 9000/victor application server, and process activity for SoftwareHouse.CrossFire.Server.exe that deviates from its normal service-account behaviour — a deserialization exploit against this component would manifest as that process spawning child processes or making outbound connections it does not make during ordinary operation, which has no benign equivalent on an access-control application server.
Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls.
Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade to C-CURE 9000 v3.20 or later