Status: NEW | Advisory ID: CVE-2026-21655
| CVE | CVE-2026-21655 |
| CVSS Score / Version | 8.7 (High) / CVSS v4.0 |
| Updated | 2026-08-06 |
| Classified as | CWE-502 (Deserialization of Untrusted Data) |
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.
This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. (NVD)
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-21655 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-21655 |