Government Advisory

Critical Flaws Found in Johnson Controls Access Control Systems

CISA · 11 Aug 2026
Key Takeaway If your business uses Johnson Controls C-CURE 9000 or Victor security systems, check your version numbers against the affected list and apply vendor patches or mitigations immediately.

The US Cybersecurity and Infrastructure Security Agency (CISA) has updated an advisory covering Johnson Controls' C-CURE 9000 access control platform and its related Victor application server and Victor Web products. The flaws, tracked as CVE-2026-21655 and CVE-2026-34496, have been rated 9.6 out of 10 on the CVSS severity scale—placing them in the critical risk category.

The vulnerabilities stem from a Server-Side Request Forgery (SSRF) issue and an 'Execution with Unnecessary Privileges' flaw. In plain terms, this means an attacker who can reach these systems over a network could potentially trick the server into making unauthorised requests, and then leverage excessive system privileges to run their own malicious code remotely—without needing physical access to the device.

Affected versions include C-CURE 9000 up to v3.10.1, Victor Application Server up to v4.10, Victor up to v7.0, and Victor Web up to v7.1. These products are widely deployed across critical infrastructure sectors worldwide, including physical security and access control systems used by businesses to manage building entry, badges, and surveillance. Johnson Controls is headquartered in Ireland and its products are used globally, meaning Australian organisations using these systems for physical security should check exposure promptly.

Johnson Controls critical infrastructure vulnerability physical security CISA advisory

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.