Product
Multiple vulnerabilities in Johnson Controls C-CURE 9000 and victor application servers, including .NET deserialization (CVE-2026-21655), allow unauthenticated remote code execution and unauthorized information disclosure.