Decision RecordActivePublished without chair review
CRT-2026-012824 Jul 2026MORNING EDITIONDaily Roundtable
Patch and isolate Johnson Controls building-security servers
Facilities using affected building-security application servers should identify exposed or remotely reachable instances, restrict access to trusted admin networks or VPN, and schedule an emergency upgrade to the vendor-confirmed fixed release while deferring broader physical-security redesign.
Current public guidance · the full record
What to do now
Under reviewAt a glanceFacilities running Johnson Controls C-CURE 9000 or Victor application servers should inventory those servers today, identify any that are internet-exposed or otherwise remotely reachable, and immediately restrict access to trusted administrative networks or VPN.
For any affected reachable C-CURE 9000 or Victor application server, schedule an emergency upgrade to the vendor-confirmed fixed release.
Treat C-CURE 9000 3.20 or later as a Roundtable-discussed version detail that still needs vendor or CISA confirmation before relying on it as the exact fixed release. Do not delay containment while planning broader physical-security redesign.
Why now
Under reviewThe Roundtable treated Johnson Controls C-CURE 9000 and Victor application servers as a same-day operational decision because exposed or remotely reachable building-security servers can sit on administrative paths that issue security authority for facilities.
The industry-impact contribution explicitly says these are not watch-list items and calls for identifying exposed servers, restricting access to trusted admin networks or VPN, and scheduling emergency upgrade.
The evidence review supports those immediate actions, while limiting exact fixed-version claims until vendor or CISA text is available.
Who is affected
Under reviewAffected operators are facilities running Johnson Controls C-CURE 9000 or Victor application servers.
The Roundtable specifically names commercial facilities, critical manufacturing, energy, government facilities, and transportation environments.
For exposed or remotely reachable C-CURE 9000 and Victor application servers, the immediate consequence is that building-security management infrastructure needs containment through trusted admin networks or VPN and emergency upgrade planning.
For C-CURE 9000 and Victor deployments that are not exposed or remotely reachable, the packet supports verification and normal risk-based scheduling rather than treating broader physical-security redesign as the same-day blocker.
What supports this
Under reviewThe industry-impact contribution says Johnson Controls C-CURE 9000 and Victor application servers should be treated as same-day business-control issues, not watch-list items, and identifies the action: find exposed or remotely reachable servers, restrict access to trusted admin networks or VPN, and schedule an emergency upgrade.
The moderator synthesis confirms the affected population as facilities using those application servers in commercial facilities, critical manufacturing, energy, government, and transportation environments, and repeats the containment-and-upgrade priority.
The final synthesis supports patching and network exposure reduction as the operational response. The evidence review supports the same-day action while separately flagging that vendor or CISA release evidence is missing for exact fixed-version wording.
How the Roundtable reached this
Under reviewThe industry-impact contributor reframed Johnson Controls C-CURE 9000 and Victor application server issues as same-day business-control work for facilities in commercial facilities, critical manufacturing, energy, government facilities, and transportation.
The moderator accepted that framing and narrowed the action to exposed or remotely reachable C-CURE 9000 and Victor application servers: restrict access to trusted admin networks or VPN and plan an emergency upgrade.
The evidence review supported the containment-and-upgrade action, but separately found that the packet does not include vendor or CISA release text confirming affected versions or the fixed release.
The final decision keeps the same-day containment posture and avoids treating broader physical-security redesign as a blocker.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 12 candidate signals.
- Linker (AI panel role)Linker evaluated 12 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 24 evidence signals; 13 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
- Arbiter (AI panel role)Arbiter produced 12 decision envelopes.
Key disagreement
Scout (AI panel role)
Operators should verify the exact vendor advisory and affected versions before change execution; non-exposed estate tuning and broader redesign are not treated as same-day blockers.
Arbiter outcome
Arbiter outcome: new decision record. The same-day patch-and-isolate action is supported and no existing decision record was linked; exact fixed-version wording is softened pending vendor confirmation.
Candidates considered
Considered 12 candidates · opened 1 · 11 not opened (11 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe emergency containment action is supported by Roundtable discussion and synthesis, but the exact affected-version and fixed-release wording remains unconfirmed in the packet.
Operators also need to verify whether each C-CURE 9000 or Victor application server is actually affected and whether it is exposed or remotely reachable.
The packet does not establish that broader physical-security redesign is needed today; it supports isolating and upgrading affected reachable servers first.
What evidence is missing
MissingThe packet does not include a Johnson Controls vendor advisory, vendor release note, or CISA advisory confirming the affected C-CURE 9000 and Victor versions or the fixed release.
The discussion names C-CURE 9000 3.20 or later, and a captured query names CVE-2026-21655, but the evidence review says the captured query is not release evidence.
Before stating a precise fixed-version claim, use vendor or government advisory text that confirms affected versions, fixed versions, and mitigation wording.
What would change this
Under reviewLower the urgency for any C-CURE 9000 or Victor application server that is verified as not affected, not exposed, and not remotely reachable.
Change the upgrade target if Johnson Controls or CISA publishes different fixed-release guidance than C-CURE 9000 3.20 or later. Increase urgency if authoritative guidance confirms active exploitation, broader affected versions, or stronger mitigations for CVE-2026-21655.
Keep containment in place until authoritative guidance and local exposure checks show the server no longer needs emergency handling.
What to watch next
Under reviewWatch for a Johnson Controls vendor advisory, vendor release note, or CISA advisory that confirms affected C-CURE 9000 and Victor versions, CVE-2026-21655 details, mitigations, and the fixed release.
If the advisory confirms C-CURE 9000 3.20 or later as the fixed release, use that version target for upgrade execution. If a server is confirmed not affected or not remotely reachable, move it out of emergency handling and track it through normal maintenance.
If vendor guidance materially changes the mitigation, update containment and upgrade plans the same day.
Evidence basis
Pierre has turned two items that might have sounded like technical alerts into same-day operational decisions. For Johnson Controls C-CURE 9000 and Victor, the affected population is not abstract: it is facilities using those application se…
Summary: Today’s decision point is not “which headline is biggest,” it is which trusted systems can issue authority on behalf of the organization. The panel treated internet-exposed PLCs as the top safety risk, while Zimbra CVE-2025-66376, …
Public value history
- 24 Jul 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 24 Jul 2026Methodology
How the panel reaches a Public Decision Record.