ctipilot.ch

Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)

cve · CVE-2026-21655

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Related entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Johnson Controls C-CURE 9000Johnson Controls victorJohnson Controls victor Application ServerJohnson Controls victor Web

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Lateral Movement TA0008

T1210Exploitation of Remote Services×1

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.

Evidence: 2026-08-28/johnson-controls-ccure9000-victor-unauth-rce · ATT&CK page ↗

Story timeline

  1. 2026-08-28Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)
    trending-vulnerabilitiesCISA publishes an unauthenticated deserialization RCE that can 'impact physical security controls' on a widely deployed access-control platform

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • isssource.com1 (50%)
  • raw.githubusercontent.com1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6) (1)

2026-08-28 · view entry permalink →

Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)

CISA's ICSA-26-204-01 (Update A, released 2026-08-11, tracking an initial release of 2026-07-23) covers three CVEs in Johnson Controls' physical access-control platform. CVE-2026-21655 (CVSS 3.1: 9.6 Critical, AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CVSS 4.0: 9.4) affects C-CURE 9000 ≤v3.10.1, victor Application Server ≤v4.10, and victor ≤v7.0. Per Johnson Controls' own remediation text, exploitation of "the vulnerable deserialization path" by an unauthenticated, adjacent-network attacker can achieve arbitrary code execution — and the blast radius extends past the server itself: "successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls" (CISA / Johnson Controls, ICSA-26-204-01, 2026-08-11). Fixed by upgrading to C-CURE 9000 v3.20+ / victor Application Server v4.20+ / victor v8.0+.

CVE-2026-21653 (same 9.6/9.4 CVSS) affects victor Web <v7.0 and lets an attacker forge server-side HTTP requests to reach internal services. CVE-2026-34496 (8.0/8.7, CWE-250 Execution with Unnecessary Privileges) affects victor Web ≤v7.1 and lets low-privilege users reach unauthorized admin pages (Users, Logs). No known public exploitation is reported for any of the three. Mitigations Johnson Controls names: isolate C-CURE 9000/victor application servers on a dedicated network segment, and restrict access to TCP/8999 to authorized systems only.

Worth flagging rather than silently resolving: CISA's own structured advisory data tags both CVE-2026-21655 and CVE-2026-21653 with CWE-918 (Server-Side Request Forgery), even though CVE-2026-21655's own summary and remediation both describe it as reaching code execution through a deserialization path — a CWE-502-class mechanism under a CWE-918 label. This is CISA's own document disagreeing with itself rather than a summarisation error introduced downstream, and it means a triage process filtering advisories by CWE class alone could misclassify this flaw's actual mechanism.

Physical access-control systems sit at the boundary between IT and physical security across government and critical-infrastructure facilities, so an unauthenticated code-execution path that names "connected clients" as reachable — explicitly including the workstations physical-security staff use — is a case where a network intrusion has a stated potential to become a physical-security failure. Triage: the detection anchor is unexpected inbound connections to TCP/8999 on any C-CURE 9000/victor application server, and process activity for SoftwareHouse.CrossFire.Server.exe that deviates from its normal service-account behaviour — a deserialization exploit against this component would manifest as that process spawning child processes or making outbound connections it does not make during ordinary operation, which has no benign equivalent on an access-control application server.

Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls.

Johnson Controls recommends the following upgrades to address the vulnerable deserialization path: Upgrade to C-CURE 9000 v3.20 or later

CISA (ICSA-26-204-01, CSAF structured advisory) 2026-08-11
vulnerability28 Aug 05:38Zmulti-sourceOpen finding ↗