CVE-2026-21653
Received
Received - Intake
Victor SSRF in CCure 9000 and victor application server
Vulnerability report for CVE-2026-21653, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-23
Last updated on: 2026-07-23
Assigner: Johnson Controls
Description
Description
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| johnson_controls | ccure_9000 | From 2.9 (inc) to 3.0 (inc) |
| johnson_controls | victor_application_server | From 2.9 (inc) to 3.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |