A vulnerability has been found in Johnson Control victor up to 2.x and classified as very critical. Impacted is an unknown function. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-21655. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.