Back to Markets
VULNERABILITYLIVEJohnson ControlsCritical InfrastructureRCEAccess Controlauto-generated
Will CVE-2026-21655 (Johnson Controls C-CURE RCE) be added to CISA KEV by end of September 2026?
72%
YES
28%
NO
0 predictions
YES
NO
80%60%40%20%
30d25d20d15d10d5dnow
Market Overview
AI GENERATEDJohnson Controls C-CURE 9000 and Victor application server versions ≤v3.10.1 are vulnerable to remote code execution (CVE-2026-21655) via unauthenticated network access. Per CISA Alerts, successful exploitation allows attackers to achieve RCE. This affects critical access-control systems in buildings, hospitals, and enterprises. Resolution via CISA KEV catalog addition (public evidence).
Primary SourceResolution Criteria
CVE-2026-21655 appears in the CISA Known Exploited Vulnerabilities Catalog by September 30, 2026, with confirmed evidence of active exploitation or public PoC demonstrating RCE.
Market Info
ClosesSeptember 30, 2026
CreatedAug 11, 2026
CategoryVulnerability
Created by@ThreatOdds
Creator accuracy0%
ResolutionCommunity vote + moderator
StatusLIVE
MARKET STATS
Total Predictions0
ClosesSeptember 30, 2026
ResolutionCommunity + Moderator
CategoryVulnerability
CREATED BY
T
@ThreatOdds
Community Market · 0% acc