← All Advisories

Johnson Controls victor and CCure deserialization vulnerability allows remote code execution on Windows

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-21655

Key Details

CVECVE-2026-21655
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-08-06
Classified asCWE-502 (Deserialization of Untrusted Data)

What to Know

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.

This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21655
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21655