criticalOther

Johnson Controls C-CURE 9000 and victor Application Server Multiple Vulnerabilities

First seen Jul 26, 2026 · Updated Jul 26, 2026 · CVSS 9.6

ICSSCADAphysical-securitySSRFdeserializationremote-code-executioncritical-infrastructureCISA-advisory

Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.

Technical Analysis

CVE-2026-21655 (CVSS 3.1: 8.8) allows an unauthenticated adjacent-network attacker to achieve arbitrary code execution on the C-CURE 9000/victor application server via a vulnerable .NET deserialization path exposed on port 8999, impacting the SoftwareHouse.CrossFire.Server.exe process and the ClientConnectionManager_NF.SynchronousServerNotification callback interface. CVE-2026-21653 (CVSS 3.1: 9.6, CRITICAL) is a Server-Side Request Forgery vulnerability in victor Web (CWE-918) that lets attackers forge server-side HTTP requests to interact with internal services and pivot laterally within the network. CVE-2026-34496 (CVSS 3.1: 8.0) is an Execution with Unnecessary Privileges flaw (CWE-250) permitting low-privilege users to access restricted pages (Users, Logs) and view sensitive account and audit data. These are physical-security/OT products rather than typical AI agent infrastructure, but if any AI agent, automation, or RAG pipeline integrates with these access-control APIs (e.g., for building automation queries or security event ingestion), a compromised application server could feed manipulated data to the agent or expose credentials/API keys used for such integrations, warranting inclusion of affected hosts in agent-adjacent asset inventories.

Affected Systems

Johnson Controls C-CURE 9000 and victor application server versions <=v2.90_v3.0; victor Web versions <=v7.1 (CVE-2026-21653 affects <v7.0); network services on TCP port 8999

Indicators of Compromise

  • No known IOCs published; no public exploitation reported by CISA at this time. Monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe and .NET deserialization payload patterns (e.g., ysoserial.net signatures) targeting port 8999.

Remediation Steps

  1. 1

    Upgrade software

    Upgrade C-CURE 9000/victor to version 3.20 or later and victor Web to version 7.0 or later to remediate the deserialization and SSRF vulnerabilities.

  2. 2

    Network segmentation

    Isolate application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems.

  3. 3

    Firewall/ACL enforcement

    Block all unnecessary inbound connections to port 8999 from untrusted network segments.

  4. 4

    Deploy IDS/IPS signatures

    Tune intrusion detection/prevention systems to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.

  5. 5

    Application whitelisting

    Enforce whitelisting on application server hosts to prevent unauthorized executables from launching via the server process.

  6. 6

    Enforce least privilege

    Run the application server process with minimum necessary privileges to limit exploitation impact.

  7. 7

    Enhanced monitoring

    Enable detailed logging and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.

  8. 8

    Disable unnecessary services

    Disable or restrict the ClientConnectionManager_NF.SynchronousServerNotification callback interface if not required.

CVE / Advisory IDs

CVE-2026-21655CVE-2026-21653CVE-2026-34496

Industries Most Exposed

Critical ManufacturingPhysical SecurityBuilding AutomationGovernment Facilities

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.