Skip to main content
System Status
Critical 18
|
High 70
|
Medium 1
|
Feed Online
UPDATED: 2026-06-11 00:00 UTC

Johnson Controls C·CURE 9000 RCE Vulnerability: ICSA-26-204-01 Advisory and Mitigation

CISA published ICSA-26-204-01 on August 11, 2026, disclosing CVE-2026-21655, a remotely exploitable code execution vulnerability in Johnson Controls C·CURE 9000 physical access control systems. With a CVSS score of 9.8 and no authentication required, the flaw affects C·CURE 9000 versions prior to 3.0.3 deployed in enterprise and critical infrastructure physical security management. This advisory covers the vulnerability details, affected versions, exploitation risk in OT-adjacent environments, and recommended mitigations.

Building Automation System Security: BACnet, BMS Hardening, and the OT-IT Convergence Risk

Building automation systems control HVAC, lighting, access control, and fire suppression across commercial and industrial facilities. As BAS deployments converge with IP networks, legacy protocols like BACnet and Modbus are now internet-adjacent — with predictable results for attack surface.