SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-21655

HIGH · CVSS 8.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A deserialization of untrusted data vulnerability in Johnson Control's Victor software on Windows versions prior to 3.0 can potentially allow an attacker to exploit the system, leading to unauthorized access or manipulation of data. Organizations utilizing affected versions of Victor should prioritize addressing this vulnerability to mitigate potential security risks associated with untrusted data handling.

CVE
CVE-2026-21655
Severity
HIGH
CVSS
8.7
EPSS
0.17%
Windows

Original NVD Description

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.