Johnson Controls just shipped a critical fix for software that controls who gets through the door at factories and other secured facilities.
An advisory update published August 11, 2026 details three vulnerabilities in Johnson Controls' C-CURE 9000 and victor physical-access-control platforms. The worst, CVE-2026-21655, scores 9.6 out of 10 and stems from an unsafe deserialization path: an attacker on the same network segment, without a password, can run arbitrary code on the application server and even reach connected client workstations. Two related bugs, a server-side request forgery flaw in victor Web (CVE-2026-21653) and a broken access control issue (CVE-2026-34496), let attackers pull data from internal systems or let low-privilege users browse user lists and audit logs they shouldn't see. Johnson Controls is telling customers to upgrade: C-CURE 9000 to v3.20, victor Application Server to v4.20, and victor to v8.0.
This isn't a leaky database. It's software that unlocks doors, and Johnson Controls markets these platforms to critical manufacturing sites worldwide. An attacker who lands on the local network, through a compromised badge reader, a misconfigured VPN, or a phished contractor, could remotely take over the server that decides who is allowed into a building. For a facility that stores hazardous materials or runs sensitive production lines, that turns an IT problem into a physical safety problem.
Until the patch lands, the mitigation advice is blunt: block port 8999 from anyone who doesn't need it, and watch for the deserialization exploit tools attackers already have off the shelf.