Johnson Controls C-CURE 9000 and Victor application server
Plan PatchCVSS 9.6ICS-CERT ICSA-26-204-01Jul 23, 2026
Johnson Controls
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Johnson Controls C-CURE 9000, victor, and victor Web application servers contain unsafe .NET deserialization vulnerabilities (CVE-2026-21655) in the request processing logic on port 8999. An attacker with network access can craft a malicious serialized object that, when deserialized by the server, triggers remote code execution through a gadget chain attack. Affected versions: C-CURE 9000 and victor versions 3.0 and earlier, victor Web versions 7.1 and earlier.
What this means
What could happen
An attacker with network access to the C-CURE 9000 or victor application server could execute arbitrary code on the server, potentially compromising the entire access control system and any dependent facilities or processes.
Who's at risk
Physical security operators and facility managers who rely on Johnson Controls C-CURE 9000 or victor access control systems. This affects badge readers, door locks, turnstiles, and related access control infrastructure in commercial buildings, data centers, and industrial facilities.
How it could be exploited
An attacker sends a malicious serialized .NET object to the application server on port 8999. The server deserializes the untrusted data without validation, triggering code execution through a gadget chain attack. This allows the attacker to run commands with the privileges of the application server process.
Prerequisites
- Network access to port 8999 on the C-CURE 9000 or victor application server
- Server must be reachable from the attacker's network segment
- No authentication credentials required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.6)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
C-CURE 9000 and victor≤ v2.90 v3.0Fix available
victor Web<v7.0Fix available
victor Web≤ v7.1Fix available
Remediation & Mitigation
0/6
Do now
0/1WORKAROUNDRestrict firewall inbound access to port 8999 to only authorized systems that require connectivity
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
victor Web
HOTFIXUpgrade victor Web to version 7.0 or later
All products
HOTFIXUpgrade C-CURE 9000 / victor to version 3.20 or later
Long-term hardening
0/3C-CURE 9000 and victor
HARDENINGIsolate the C-CURE 9000 and victor application servers on a dedicated network segment, separate from general IT networks
All products
HARDENINGDeploy IDS/IPS signatures to detect .NET deserialization exploit patterns (e.g., ysoserial.net) targeting port 8999
HARDENINGEnforce application whitelisting on the application server hosts to prevent unauthorized executables from running
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9e2b250e-7141-4d3f-976c-3c2101006907Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.