CVE-2026-21653: CCure and Victor Application Server - Server Side Request Forgery
Published Jul 23, 2026
·Updated
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Affected Software
2 affected components
Johnson Controls CCure 9000>=2.9<=3.0
Johnson Controls victor application server>=2.9<=3.0
Event History
Jul 23, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-21653?
The severity of CVE-2026-21653 is rated high with a score of 7.2.
2
What systems are affected by CVE-2026-21653?
CVE-2026-21653 affects CCure 9000 and Victor application server versions from 2.9 through 3.0.
3
How do I fix CVE-2026-21653?
To fix CVE-2026-21653, update to the latest version of CCure 9000 or Victor application server as provided by Johnson Controls.
4
What is the nature of the vulnerability in CVE-2026-21653?
CVE-2026-21653 is a Server Side Request Forgery (SSRF) vulnerability.
5
When was CVE-2026-21653 published?
CVE-2026-21653 was published on July 23, 2026.