securityonline.info 7/29/2026, 5:01:17 PM · external

Johnson Controls apps flaw CVE-2026-21653 enables RCE

Johnson Controls apps flaw CVE-2026-21653 enables RCE
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Not in KEV
Patch Patch Status Unknown

CISA published advisory ICSA-26-204-01 on July 23, 2026, detailing three vulnerabilities in Johnson Controls' C-CURE 9000 and victor application servers. The most critical flaw, CVE-2026-21653, has a CVSS score of 9.6 and can lead to remote code execution (CVE-2026-21655) and server-side request forgery (CVE-2026-21653). While no exploitation has been confirmed, patches are available, and updates to version 3.0 or 7.1 are recommended.

These vulnerabilities could affect physical security systems, posing risks to large facilities. Attackers can exploit these flaws through deserialization of untrusted data or tricking the server into sending unauthorized requests. The affected versions include C-CURE 9000 and victor up to v2.90_v3.0, with mitigation steps including server isolation and IDS/IPS tuning.

View Primary Source Via securityonline.info

Article by CyberSIXT