Junglewise Threat Intelligence

CVE-2026-21655: Johnson Controls victor Deserialization of Untrusted Data on Windows

CVE-2026-21655 · Severity: info · CVSS 8.7 · Published 2026-07-23

Vendors: Johnson Controls.

Executive brief

Johnson Controls victor is a video management system used to manage security cameras and surveillance data on Windows platforms. A vulnerability in how the software processes data could allow an attacker on the same local network to take control of the system. This could lead to unauthorized access to surveillance feeds, data theft, or disruption of security operations.

Technical details

A deserialization vulnerability (CWE-502) exists in Johnson Controls victor running on Windows. The flaw stems from the application improperly processing serialized data from untrusted sources, which can be leveraged by an attacker to achieve remote code execution (CAPEC-586). The attack vector is restricted to the adjacent network (AV:A), but requires no authentication or user interaction. The vulnerability affects versions 2.9 through 3.0. Users are advised to consult Johnson Controls security advisories for patching information.

Affected products

  • Johnson Controls victor 2.9 to 3.0

Timeline

  • 2026-07-23: advisory: Initial disclosure by Johnson Controls and NVD publication.

References