View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update A) are affected:
C-CURE 9000 <=v3.10.1 (CVE-2026-21655)
victor Application Server <=v4.10 (CVE-2026-21655)
victor <=v7.0 (CVE-2026-21655)
victor Web
victor Web <=v7.1 (CVE-2026-34496)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.6
Johnson Con…
📰 来源: CISA 安全公告
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。