← All Advisories

Johnson Controls CCure 9000 and victor application server SSRF vulnerability in versions 2.9 through 3.0

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-21653

Key Details

CVECVE-2026-21653
CVSS Score / Version7.2 (High) / CVSS v4.0
Updated2026-07-30
Classified asCWE-918 (Server-Side Request Forgery (SSRF))

What to Know

Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.

This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-21653
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-21653