Critical Vulnerabilities in Johnson Controls C-CURE 9000 and victor Application Servers
Johnson Controls has released security updates for its C-CURE 9000 and victor application servers, which are used to manage physical security systems. These vulnerabilities could allow unauthorized users to take control of these systems or access sensitive data. Organizations using these products should update to the latest versions immediately.

English Brief
Johnson Controls has released security updates for its C-CURE 9000 and victor application servers, which are used to manage physical security systems. These vulnerabilities could allow unauthorized users to take control of these systems or access sensitive data. Organizations using these products should update to the latest versions immediately.
الموجز العربي
ثغرات أمنية حرجة في خوادم تطبيقات Johnson Controls C-CURE 9000 و victor
أصدرت شركة Johnson Controls تحديثات أمنية لخوادم تطبيقات C-CURE 9000 و victor المستخدمة في إدارة أنظمة الأمن المادي. قد تسمح هذه الثغرات لمستخدمين غير مصرح لهم بالتحكم في هذه الأنظمة أو الوصول إلى بيانات حساسة. يجب على المؤسسات التي تستخدم هذه المنتجات التحديث إلى أحدث الإصدارات فوراً.
- 1Upgrade C-CURE 9000/victor to v3.20 or later.
- 2Upgrade victor Web to v7.0 or later.
- 3Restrict network access to port 8999 to trusted management subnets only.
English Advisory
// Intelligence Summary
Multiple critical vulnerabilities have been identified in Johnson Controls C-CURE 9000 and victor application servers, including remote code execution (RCE) via insecure deserialization and Server-Side Request Forgery (SSRF). These flaws, tracked as CVE-2026-21655, CVE-2026-21653, and CVE-2026-34496, pose significant risks to critical infrastructure and physical security integrity.
التقرير العربي
// ملخص استخباراتي
تم تحديد ثغرات أمنية حرجة متعددة في خوادم تطبيقات Johnson Controls C-CURE 9000 و victor، بما في ذلك تنفيذ التعليمات البرمجية عن بُعد (RCE) عبر إلغاء تسلسل غير آمن (Insecure Deserialization) وتزوير الطلبات من جانب الخادم (SSRF). هذه الثغرات، المرقمة بـ CVE-2026-21655 و CVE-2026-21653 و CVE-2026-34496، تشكل مخاطر كبيرة على البنية التحتية الحيوية وسلامة أنظمة الأمن المادي.
// Technical Context
CVE-2026-21655 involves a .NET deserialization vulnerability allowing unauthenticated remote code execution on the application server. CVE-2026-21653 is an SSRF vulnerability in the victor Web application that permits unauthorized interaction with internal services. CVE-2026-34496 allows privilege escalation, enabling low-privileged users to access sensitive logs and user information.
// السياق الفني
تتضمن CVE-2026-21655 ثغرة في إلغاء تسلسل .NET تسمح بتنفيذ تعليمات برمجية عن بُعد دون الحاجة إلى مصادقة. وتعد CVE-2026-21653 ثغرة SSRF في تطبيق ويب victor تسمح بالتفاعل غير المصرح به مع الخدمات الداخلية. أما CVE-2026-34496 فتسمح بتصعيد الامتيازات، مما يتيح للمستخدمين ذوي الصلاحيات المنخفضة الوصول إلى سجلات حساسة ومعلومات المستخدم.
// Exposure Notes
Affected products include C-CURE 9000 and victor versions 3.0 and older, and victor Web versions 7.1 and older. Attackers can leverage these flaws to gain administrative control or perform lateral movement within the network.
// ملاحظات التعرض
تشمل المنتجات المتأثرة C-CURE 9000 و victor الإصدار 3.0 فما دون، وvictor Web الإصدار 7.1 فما دون. يمكن للمهاجمين استغلال هذه العيوب لاكتساب تحكم إداري أو القيام بحركات جانبية داخل الشبكة.
// Defensive Priority
Immediate upgrading of C-CURE 9000/victor to version 3.20 or later and victor Web to 7.0 or later is required. Organizations should restrict access to port 8999, implement strict firewall rules, and deploy IDS/IPS signatures tuned for .NET deserialization payloads.
// أولوية الدفاع
يعد التحديث الفوري لـ C-CURE 9000/victor إلى الإصدار 3.20 أو أحدث، وvictor Web إلى الإصدار 7.0 أو أحدث أمراً ضرورياً. يجب على المؤسسات تقييد الوصول إلى المنفذ 8999، وتطبيق قواعد جدار حماية صارمة، ونشر توقيعات IDS/IPS المخصصة لاكتشاف حمولات إلغاء تسلسل .NET.
Mitigation Checklist
- 1Upgrade C-CURE 9000/victor to v3.20 or later.
- 2Upgrade victor Web to v7.0 or later.
- 3Restrict network access to port 8999 to trusted management subnets only.
- 4Apply firewall rules to block unsolicited inbound connections to application server hosts.
- 5Enable IDS/IPS detection for ysoserial.net patterns.
- 6Audit system for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.
قائمة إجراءات التخفيف
- 1قم بترقية C-CURE 9000/victor إلى الإصدار 3.20 أو أحدث.
- 2قم بترقية victor Web إلى الإصدار 7.0 أو أحدث.
- 3قيد الوصول إلى الشبكة للمنفذ 8999 ليشمل فقط الشبكات الفرعية للإدارة الموثوقة.
- 4طبق قواعد جدار الحماية لمنع الاتصالات الواردة غير المطلوبة إلى خوادم التطبيقات.
- 5قم بتفعيل كشف IDS/IPS لأنماط ysoserial.net.
- 6قم بمراجعة النظام بحثاً عن أي إنشاء غير طبيعي للعمليات بواسطة SoftwareHouse.CrossFire.Server.exe.
- SoftwareHouse.CrossFire.Server.exe
# Remediation Checklist
1. Upgrade C-CURE 9000/victor to v3.20 or later.
2. Upgrade victor Web to v7.0 or later.
3. Restrict network access to port 8999 to trusted management subnets only.
4. Apply firewall rules to block unsolicited inbound connections to application server hosts.
5. Enable IDS/IPS detection for ysoserial.net patterns.
6. Audit system for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.