Security/ physical-security · ics-vulnerability · critical-infrastructure · cisa

Johnson Controls Patches Critical Bug in Physical Security Software

A critical 9.6-rated flaw in Johnson Controls physical-access-control software lets an unauthenticated attacker on the network execute code and unlock doors.

Johnson Controls just shipped a critical fix for software that controls who gets through the door at factories and other secured facilities.

An advisory update published August 11, 2026 details three vulnerabilities in Johnson Controls' C-CURE 9000 and victor physical-access-control platforms. The worst, CVE-2026-21655, scores 9.6 out of 10 and stems from an unsafe deserialization path: an attacker on the same network segment, without a password, can run arbitrary code on the application server and even reach connected client workstations. Two related bugs, a server-side request forgery flaw in victor Web (CVE-2026-21653) and a broken access control issue (CVE-2026-34496), let attackers pull data from internal systems or let low-privilege users browse user lists and audit logs they shouldn't see. Johnson Controls is telling customers to upgrade: C-CURE 9000 to v3.20, victor Application Server to v4.20, and victor to v8.0.

This isn't a leaky database. It's software that unlocks doors, and Johnson Controls markets these platforms to critical manufacturing sites worldwide. An attacker who lands on the local network, through a compromised badge reader, a misconfigured VPN, or a phished contractor, could remotely take over the server that decides who is allowed into a building. For a facility that stores hazardous materials or runs sensitive production lines, that turns an IT problem into a physical safety problem.

Until the patch lands, the mitigation advice is blunt: block port 8999 from anyone who doesn't need it, and watch for the deserialization exploit tools attackers already have off the shelf.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →