SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-21653

HIGH · CVSS 7.2 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A Server Side Request Forgery (SSRF) vulnerability exists in Johnson Controls' CCure 9000 and Victor application server, impacting versions 2.9 through 3.0. This flaw could allow an attacker to manipulate server requests, potentially leading to unauthorized access to internal resources. Organizations using these affected versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-21653
Severity
HIGH
CVSS
7.2
EPSS
0.23%

Original NVD Description

Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.