Johnsoncontrols
Johnsoncontrols Victor Application Server: vulnerabilities and CVEs
Johnsoncontrols Victor Application Server has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs2
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21655 | High (8.7) | 0.49% | — | Jul 23, 2026 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0;… |
| CVE-2026-21653 | High (7.2) | 0.39% | — | Jul 23, 2026 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. |
Other products by Johnsoncontrols
Metasys Extended Application AND Data Server · 12Metasys Application AND Data Server · 11Metasys Open Application Server · 10Exacqvision WEB Service · 8Frick Controls Quantum HD Firmware · 6Metasys System Configuration Tool · 4Exacqvision Server · 4Metasys System · 3C-cure 9000 Firmware · 3FMS Employee · 3Istar Ultra Firmware · 2Airwall · 2