High SEVERITY — Vulnerability

CVE-2026-21655 — Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and J

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.

Platform
Windows Server
CVE Record
CVE-2026-21655
CVSS Score
8.7/10
Published
23 July 2026
Views
28
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.

This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.

Assessment

  • CVE: CVE-2026-21655
  • CVSS base score: 8.7
  • Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

Windows Server — Related Advisories

VIEW ALL →