ScrollInsights

Vulnerabilities & exploits

Four CISA industrial control advisories detail critical code execution and authentication bypasses

Johnson Controls, ABB and Acrisure systems face multiple vulnerabilities ranging from hardcoded credentials to unauthenticated arbitrary code execution.

Disclaimer

This article was produced by Scroll Insights News Desk using automated systems and published under our standing editorial policy. It is compiled from the primary sources linked above and is provided for general information only — it is not legal, financial, investment, tax or professional advice, and no decision should be taken on it without independent verification against those sources. Errors can be reported to corrections@scrollinsights.com and are corrected on the record.

CISA has published four industrial control system advisories covering vulnerabilities in Johnson Controls security and building management systems, ABB industrial IoT platforms, and Acrisure vehicle anti-theft hardware.

Johnson Controls C-CURE 9000 and victor: critical remote code execution

Johnson Controls C-CURE 9000 access control systems and victor application servers face CVE-2026-21655, a CVSS 9.6 critical vulnerability allowing unauthenticated attackers on an adjacent network to achieve arbitrary code execution on C-CURE 9000, victor application server, victor clients, and connected devices under certain circumstances. C-CURE 9000 versions 3.10.1 and earlier are affected, as are victor application server versions 4.10 and earlier and victor versions 7.0 and earlier. Johnson Controls recommends upgrading C-CURE 9000 to v3.20 or later, victor application server to v4.20 or later, and victor to v8.0 or later. The advisory was initially published July 23, 2026 and updated August 11, 2026.

victor Web versions 7.0 and earlier also face CVE-2026-21653, a CVSS 9.6 critical flaw permitting attackers to forge server-side HTTP requests from the victor Web application, potentially enabling unauthorized information disclosure or lateral movement within networks. Additionally, victor Web versions 7.1 and earlier are vulnerable to CVE-2026-34496, which has a CVSS 8.0 high severity score and allows low privilege users to access unauthorized pages such as Users and Logs, potentially enabling further attacks or unauthorized administrative actions.

Johnson Controls TL280: hardcoded credentials

Johnson Controls TL280 devices running firmware versions before 5.63 contain CVE-2026-27871, a CVSS 4.1 medium severity flaw involving hardcoded credentials embedded in the firmware that can be used to access system login and other areas of the application. Johnson Controls recommends applying firmware update 5.63 to address the vulnerability. The advisory was published August 6, 2026.

Acrisure vehicle anti-theft systems: shared Bluetooth key weakness

Acrisure KARR BT and DR-100 automotive anti-theft systems are affected by CVE-2026-18411, a CVSS 8.1 high severity vulnerability affecting KARR Security System and SWDS dealer-installed systems that use a shared Bluetooth authentication key across affected devices. Attackers within Bluetooth range can leverage this weakness to issue unauthorized commands to vehicles, including door unlocking and engine immobilization. Acrisure firmware versions before July 20, 2026 are affected. Acrisure Protection Group released a firmware update on July 20, 2026 to address the flaw. The advisory was published August 4, 2026.

ABB Ability Zenon: multiple MongoDB vulnerabilities

ABB Ability Zenon with IIoT services using MongoDB version 4.2 is affected by nine MongoDB vulnerabilities, including CVE-2025-14847, which involves mismatched length fields in Zlib compressed protocol headers that may allow an unauthenticated client to read uninitialized heap memory. Older MongoDB vulnerabilities include CVE-2020-7921, which permits users with valid credentials to bypass IP whitelisting protections; CVE-2020-7923, CVE-2020-7925, CVE-2020-7928, and CVE-2020-7929, which permit authorized or unauthenticated attackers to trigger denial of service; and CVE-2021-20330, CVE-2021-20333, CVE-2021-32036, and CVE-2021-32040, which enable denial of service, log manipulation, or information access. ABB recommends either uninstalling IIoT Services wherever not required or replacing the bundled MongoDB version 4.2 with a supported version. The advisory was published August 6, 2026.

Sources