CVE Tools

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

The Hacker NewsBy The Hacker News

PatchArcGIS Server

Our summary

A critical security flaw in Esri ArcGIS Server 12.0 and earlier versions has been patched following reports of potential unauthenticated file access. The vulnerability, tracked as CVE-2026-9181 with a CVSS score of 9.8/7.5, allowed attackers to access sensitive files by sending specially crafted path parameters. This flaw resided in the REST Uploads resource due to insufficient validation of inputs, enabling directory traversal attacks. Horizon3.ai highlighted the risk, noting that no authentication was required to exploit it. Users are strongly advised to update to the latest version to mitigate exposure.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store