๐Ÿ” CVE Alert

CVE-2026-21655

UNKNOWN 0.0

C-CURE 9000 and Victor application server - Deserialization of Untrusted Data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.

CWE CWE-502
Vendor johnson control
Product victor
Published Jul 23, 2026
Last Updated Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for johnson control victor

Be the first to know when new unknown vulnerabilities affecting johnson control victor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Johnson Control / victor
0 < 8.0
Johnson Controls / CCure 9000
0 < 3.2
Johnson Controls / Victor Application Server
0 < 4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
johnsoncontrols.com: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories