Back to Markets
VULNERABILITYLIVEJohnson ControlsRCECritical InfrastructureAccess Controlauto-generated

Will Johnson Controls C-CURE RCE vulnerability be actively exploited before Sept 2026?

63%
YES
37%
NO
0 predictions
YES
NO
60%50%40%
30d25d20d15d10d5dnow

Market Overview

AI GENERATED

CISA has disclosed remote code execution vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server (≤v2.90_v3.0 and ≤v7.1). These systems manage physical access control and are widely deployed in critical infrastructure.

Primary Source

Resolution Criteria

CISA KEV addition; vendor confirmation of in-the-wild exploitation; or public disclosure by Mandiant, CrowdStrike, or CISA alert of active RCE exploitation campaigns by Sept 30, 2026.

Market Info

ClosesOctober 1, 2026
CreatedJul 23, 2026
CategoryVulnerability
Created by@ThreatOdds
Creator accuracy0%
ResolutionCommunity vote + moderator
StatusLIVE

MARKET STATS

Total Predictions0
ClosesOctober 1, 2026
ResolutionCommunity + Moderator
CategoryVulnerability
Beta Feedback