Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586.

This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.

Project Subscriptions

Vendors Products
Johnson Control Subscribe
Johnson Controls Subscribe
Ccure 9000 Subscribe
Victor Application Server Subscribe
Johnsoncontrols Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0. Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
First Time appeared Johnson Controls
Johnson Controls ccure 9000
Johnson Controls victor Application Server
CPEs cpe:2.3:a:johnson_controls:ccure_9000:*:*:*:*:*:*:*:*
cpe:2.3:a:johnson_controls:victor_application_server:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls ccure 9000
Johnson Controls victor Application Server

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols victor
Vendors & Products Johnsoncontrols
Johnsoncontrols victor

Sat, 25 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
Title C-CURE 9000 and Victor application server - Deserialization of Untrusted Data
First Time appeared Johnson Control
Johnson Control victor
Weaknesses CWE-502
CPEs cpe:2.3:a:johnson_control:victor:*:*:windows:*:*:*:*:*
Vendors & Products Johnson Control
Johnson Control victor
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-06T17:49:48.709Z

Reserved: 2026-01-02T13:23:28.169Z

Link: CVE-2026-21655

cve-icon Vulnrichment

Updated: 2026-07-24T13:34:42.465Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-23T21:17:03.810

Modified: 2026-08-06T22:17:00.500

Link: CVE-2026-21655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:45:05Z

Weaknesses