<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Victor Application Server - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/victor-application-server/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 17:36:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/victor-application-server/feed.xml" rel="self" type="application/rss+xml"/><item><title>Critical Vulnerabilities in Johnson Controls C-CURE 9000 and victor</title><link>https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-vulnerabilities/</link><pubDate>Tue, 11 Aug 2026 17:36:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-vulnerabilities/</guid><description>Multiple vulnerabilities in Johnson Controls C-CURE 9000 and victor application servers, including .NET deserialization (CVE-2026-21655), allow unauthenticated remote code execution and unauthorized information disclosure.</description><content:encoded><![CDATA[<p>Johnson Controls has disclosed multiple critical vulnerabilities affecting the C-CURE 9000 and victor application server platforms. The most severe flaw, CVE-2026-21655, involves a .NET deserialization vulnerability that allows an unauthenticated attacker on an adjacent network to execute arbitrary code with elevated privileges. Additionally, CVE-2026-21653 permits Server-Side Request Forgery (SSRF) within the victor Web application, while CVE-2026-34496 allows low-privileged users to access restricted pages, including logs and user configurations.</p>
<p>These vulnerabilities impact physical security systems globally, particularly within the Critical Manufacturing sector. Attackers can leverage these flaws to gain full control over the application server process, potentially impacting physical security controls or exfiltrating sensitive system data. Johnson Controls recommends immediate upgrades to C-CURE 9000 v3.20, victor Application Server v4.20, or victor v8.0 to remediate these issues.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in complete system compromise, including unauthorized remote code execution on the application server and connected client workstations. An attacker could bypass authentication to view sensitive audit logs and user account information, or pivot within the internal network to gain further control over physical security infrastructure. Given the CVSS score of 9.6, these vulnerabilities represent a significant risk to the integrity and confidentiality of industrial security environments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of C-CURE 9000, victor Application Server, and victor to the latest patched versions as specified in the JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 advisories.</li>
<li>Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted or non-essential network segments.</li>
<li>Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting the identified application services.</li>
<li>Enforce application whitelisting on all application server hosts to restrict the execution of unauthorized binaries.</li>
<li>Audit the application server process <code>SoftwareHouse.CrossFire.Server.exe</code> for anomalous process creation or unauthorized child process execution.</li>
<li>Disable the <code>ClientConnectionManager_NF.SynchronousServerNotification</code> callback interface if it is not required for daily business operations.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>