{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/victor-application-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-21655"},{"id":"CVE-2026-21653"},{"id":"CVE-2026-34496"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["C-CURE 9000","victor Application Server","victor","victor Web"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Johnson Controls"],"content_html":"\u003cp\u003eJohnson Controls has disclosed multiple critical vulnerabilities affecting the C-CURE 9000 and victor application server platforms. The most severe flaw, CVE-2026-21655, involves a .NET deserialization vulnerability that allows an unauthenticated attacker on an adjacent network to execute arbitrary code with elevated privileges. Additionally, CVE-2026-21653 permits Server-Side Request Forgery (SSRF) within the victor Web application, while CVE-2026-34496 allows low-privileged users to access restricted pages, including logs and user configurations.\u003c/p\u003e\n\u003cp\u003eThese vulnerabilities impact physical security systems globally, particularly within the Critical Manufacturing sector. Attackers can leverage these flaws to gain full control over the application server process, potentially impacting physical security controls or exfiltrating sensitive system data. Johnson Controls recommends immediate upgrades to C-CURE 9000 v3.20, victor Application Server v4.20, or victor v8.0 to remediate these issues.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in complete system compromise, including unauthorized remote code execution on the application server and connected client workstations. An attacker could bypass authentication to view sensitive audit logs and user account information, or pivot within the internal network to gain further control over physical security infrastructure. Given the CVSS score of 9.6, these vulnerabilities represent a significant risk to the integrity and confidentiality of industrial security environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of C-CURE 9000, victor Application Server, and victor to the latest patched versions as specified in the JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 advisories.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted or non-essential network segments.\u003c/li\u003e\n\u003cli\u003eDeploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting the identified application services.\u003c/li\u003e\n\u003cli\u003eEnforce application whitelisting on all application server hosts to restrict the execution of unauthorized binaries.\u003c/li\u003e\n\u003cli\u003eAudit the application server process \u003ccode\u003eSoftwareHouse.CrossFire.Server.exe\u003c/code\u003e for anomalous process creation or unauthorized child process execution.\u003c/li\u003e\n\u003cli\u003eDisable the \u003ccode\u003eClientConnectionManager_NF.SynchronousServerNotification\u003c/code\u003e callback interface if it is not required for daily business operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T17:36:47Z","date_published":"2026-08-11T17:36:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-vulnerabilities/","summary":"Multiple vulnerabilities in Johnson Controls C-CURE 9000 and victor application servers, including .NET deserialization (CVE-2026-21655), allow unauthenticated remote code execution and unauthorized information disclosure.","title":"Critical Vulnerabilities in Johnson Controls C-CURE 9000 and victor","url":"https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Victor Application Server","version":"https://jsonfeed.org/version/1.1"}