CVE-2026-21653
Severity CVSS v4.0:
HIGH
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
23/07/2026
Last modified:
24/07/2026
Description
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.<br />
<br />
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH



