What is CVE-2026-21653?
This critical vulnerability is a Server-Side Request Forgery (SSRF) flaw found in Johnson Controls' CCure 9000 and Victor Application Server products. Affecting versions 2.9 through 3.0, the flaw allows a remote attacker to make unauthorized requests to internal network resources from the server. Affected systems should immediately apply the security updates provided by the vendor.
Azərbaycanca: Bu kritik zəiflik Johnson Controls-un CCure 9000 və Victor Application Server proqramlarında aşkarlanmış Server-Side Request Forgery (SSRF) boşluğudur. Məhsulun 2.9-dan 3.0-a qədər olan versiyalarına təsir edən bu qüsur uzaqdan hücum edən şəxsə serverin daxili şəbəkə resurslarına icazəsiz sorğular göndərməsinə imkan verir. Təsirə məruz qalan sistemlərdə dərhal istehsalçının təqdim etdiyi təhlükəsizlik yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which Johnson Controls products are affected by the CVE-2026-21653 vulnerability?
This critical SSRF vulnerability affects Johnson Controls' CCure 9000 and Victor Application Server products.
What action should be taken to protect against CVE-2026-21653?
Affected systems should immediately apply the security updates provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.