ICSA-26-204-01
·
Published 2026-07-23
·
View on CISA ICS-CERT ↗
Johnson Controls C-CURE 9000 and Victor application server
CVSS 9.6
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
CVEs (3)
Remediations
- Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1).
- Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity.
- Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.
- Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.
- Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.
- Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.
- Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.
- Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
- (CVE-2026-21653, CVE-2026-34496) Update all victor Web installations to version 7.0 or later, which contains the fix for this vulnerability. The fix has been validated through independent retest.
Affected Vendors
Johnson Controls
Affected Products (3)
Johnson Controls
·
C-CURE 9000 and victor
<=v2.90_v3.0
Johnson Controls
·
victor Web
<v7.0
Johnson Controls
·
victor Web
<=v7.1
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more