CVE-2026-21655
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
Published:Jul 23, 2026
Last Modified:Aug 6, 2026
EPS:Jul 23, 2026
EPSS Score:0.00165
CVSS Score:8.7
Affected Products
Vendor
Product
Action
Vendor
Johnson Control
Product
Victor
Johnson Control
Victor
Vendor
Johnson Controls
Product
Ccure 9000
Johnson Controls
Ccure 9000
Vendor
Johnson Controls
Product
Victor Application Server
Johnson Controls
Victor Application Server
Vendor
Johnsoncontrols
Product
Victor
Johnsoncontrols
Victor
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
