Johnson Controls C-CURE 9000 and victor Application Server Multiple Vulnerabilities
First seen Jul 26, 2026 · Updated Jul 26, 2026 · CVSS 9.6
Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.
Technical Analysis
CVE-2026-21655 (CVSS 3.1: 8.8) allows an unauthenticated adjacent-network attacker to achieve arbitrary code execution on the C-CURE 9000/victor application server via a vulnerable .NET deserialization path exposed on port 8999, impacting the SoftwareHouse.CrossFire.Server.exe process and the ClientConnectionManager_NF.SynchronousServerNotification callback interface. CVE-2026-21653 (CVSS 3.1: 9.6, CRITICAL) is a Server-Side Request Forgery vulnerability in victor Web (CWE-918) that lets attackers forge server-side HTTP requests to interact with internal services and pivot laterally within the network. CVE-2026-34496 (CVSS 3.1: 8.0) is an Execution with Unnecessary Privileges flaw (CWE-250) permitting low-privilege users to access restricted pages (Users, Logs) and view sensitive account and audit data. These are physical-security/OT products rather than typical AI agent infrastructure, but if any AI agent, automation, or RAG pipeline integrates with these access-control APIs (e.g., for building automation queries or security event ingestion), a compromised application server could feed manipulated data to the agent or expose credentials/API keys used for such integrations, warranting inclusion of affected hosts in agent-adjacent asset inventories.
Affected Systems
Johnson Controls C-CURE 9000 and victor application server versions <=v2.90_v3.0; victor Web versions <=v7.1 (CVE-2026-21653 affects <v7.0); network services on TCP port 8999
Indicators of Compromise
- No known IOCs published; no public exploitation reported by CISA at this time. Monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe and .NET deserialization payload patterns (e.g., ysoserial.net signatures) targeting port 8999.
Remediation Steps
- 1
Upgrade software
Upgrade C-CURE 9000/victor to version 3.20 or later and victor Web to version 7.0 or later to remediate the deserialization and SSRF vulnerabilities.
- 2
Network segmentation
Isolate application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems.
- 3
Firewall/ACL enforcement
Block all unnecessary inbound connections to port 8999 from untrusted network segments.
- 4
Deploy IDS/IPS signatures
Tune intrusion detection/prevention systems to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.
- 5
Application whitelisting
Enforce whitelisting on application server hosts to prevent unauthorized executables from launching via the server process.
- 6
Enforce least privilege
Run the application server process with minimum necessary privileges to limit exploitation impact.
- 7
Enhanced monitoring
Enable detailed logging and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.
- 8
Disable unnecessary services
Disable or restrict the ClientConnectionManager_NF.SynchronousServerNotification callback interface if not required.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.