HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in Johnson Controls C‑CURE 9000 & Victor Application Server (CVE‑2026‑21655)

A CVSS 9.6 SSRF/privilege‑escalation flaw (CVE‑2026‑21655) in Johnson Controls C‑CURE 9000 and Victor servers permits unauthenticated attackers to run arbitrary code, threatening physical‑security controls. For SOC 2‑ready organizations, the incident underscores the need for documented patch‑management and continuous monitoring of third‑party OT assets.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Critical Remote Code Execution in Johnson Controls C‑CURE 9000 & Victor Application Server (CVE‑2026‑21655)

What It Is — A critical server‑side request forgery (SSRF) and privilege‑escalation flaw (CVSS 3.0 9.6) in Johnson Controls C‑CURE 9000 and Victor application server allows an unauthenticated attacker on the same network to execute arbitrary code on the server and on connected workstations.

Exploitability — The vulnerability is publicly disclosed (CVE‑2026‑21655) and can be weaponized without credentials; proof‑of‑concept code is available in the public advisory.

Affected Products — Johnson Controls C‑CURE 9000 (versions ≤ v2.90_v3.0) and Victor application server (versions ≤ v7.1).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 System Operations (CC6.1) requires documented evidence that critical production systems are protected against unauthenticated code execution; this flaw highlights a gap in your patch‑management evidence.
  • Continuous control monitoring must capture vendor‑issued patches and remediation timelines to demonstrate due diligence to auditors and enterprise customers.
  • Physical‑security‑related IT assets are in‑scope for Critical Manufacturing environments; a breach could trigger downstream compliance obligations (e.g., NIST 800‑171, ISO 27001).

Recommended Actions

  • Inventory all C‑CURE 9000 and Victor instances; verify version numbers against the advisory.
  • Apply Johnson Controls’ remediation patches immediately; document patch dates and responsible personnel.
  • Map the patch‑management activity to SOC 2 CC6.1 and CC7.2 controls, capturing screenshots or automated logs as audit evidence.
  • Enable continuous vulnerability monitoring for third‑party OT/ICS products to surface future advisories automatically.
  • Review network segmentation to ensure that only authorized segments can reach the application servers.

Source: CISA Advisory – ICSA‑26‑204‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →