Johnson Controls C-CURE 9000 and Victor application server Vulnerabilities
Johnson Controls C-CURE 9000 and Victor application server have been found vulnerable to Server-Side Request Forgery (SSRF) and Execution with Unnecessary Privileges. Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution.
Intelligence analysis by Llama
Johnson Controls C-CURE 9000 and Victor application server have been found vulnerable to Server-Side Request Forgery (SSRF) and Execution with Unnecessary Privileges. Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution. The affected versions are C-CURE 9000 and victor <=v2.90_v3.0 and victor Web <=v7.1. The vulnerabilities have bee…
Imagine you have a super powerful computer that controls many things, like locks and alarms. If someone hacks into this computer, they could do bad things like unlock doors or turn off alarms. This is what happened with Johnson Controls C-CURE 9000 and Victor application server. They have a bug that lets hackers do bad things. To fix this, Johnson Controls is telling people to update their software to the latest version.
Analysis
Vulnerabilities in Johnson Controls C-CURE 9000 and Victor Application Server
Johnson Controls C-CURE 9000 and Victor application server have been found vulnerable to Server-Side Request Forgery (SSRF) and Execution with Unnecessary Privileges. Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution.
The affected versions are C-CURE 9000 and victor <=v2.90_v3.0 and victor Web <=v7.1. The vulnerabilities have been assigned CVE-2026-21655 and CVE-2026-21653.
Mitigation and Remediation
Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation:
- Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1).
- Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity.
- Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.
- Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.
- Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.
- Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.
- Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.
- Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
Key points
- Johnson Controls C-CURE 9000 and Victor application server have been found vulnerable to Server-Side Request Forgery (SSRF) and Execution with Unnecessary Privileges.
- Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution.
- The affected versions are C-CURE 9000 and victor <=v2.90_v3.0 and victor Web <=v7.1.
- The vulnerabilities have been assigned CVE-2026-21655 and CVE-2026-21653.
- Johnson Controls recommends upgrading to the latest version of the software to mitigate the risk of exploitation.
If the vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server are addressed promptly, the risk of exploitation can be significantly reduced. This will help to prevent potential security breaches and protect physical security controls.
If the vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server are not addressed promptly, the risk of exploitation will remain, and potential security breaches can occur. This could lead to unauthorized access to sensitive information and compromise physical security controls.



