What is CVE-2026-21655?
CVE-2026-21655 is a deserialization of untrusted data vulnerability in Johnson Controls Victor on Windows. It may allow remote code execution (CApec-586), affecting versions from 2.9 before 3.0. Users should update to the latest version.
Azərbaycanca: CVE-2026-21655, Windows üzərində işləyən Johnson Controls Victor proqramında etibarsız məlumatların deserializasiyası zəifliyidir. Bu, uzaqdan kod icrasına (CApec-586) səbəb ola bilər. Təsirə məruz qalan 2.9-dan 3.0-a qədər versiyaları istifadə edənlər proqramı yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which operating system versions of Johnson Controls Victor are affected by CVE-2026-21655?
This vulnerability affects Johnson Controls Victor running on Windows.
What type of threat can CVE-2026-21655 lead to and which versions are affected?
This vulnerability may allow remote code execution (CApec-586). Affected versions range from 2.9 to before 3.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.