A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
In plain language
Written by AI from the record
CVE-2026-16606 is a security hole in Fujitsu Software openFT for Linux and Oracle Solaris that lets an attacker run code over the network without logging in; most small businesses should treat this as a serious patching priority if your server is exposed to the network.
Unauthenticated remote code execution (pre-auth RCE) in Fujitsu Software openFT for Linux and Oracle Solaris; an attacker can trigger arbitrary code execution over the network without any authentication.
If you're affected
Full server takeover
Malware installation
Service outage
Data theft risk
What is it
openFT is the server software that helps systems exchange files. This vulnerability is like leaving a front door unlocked—an attacker can reach the server over the network and run their own code without logging in. If they succeed, they could take over the machine or disrupt your file services.
Who is affected
This matters if you run Fujitsu Software openFT on Linux or Oracle Solaris and your openFT server can be reached from a network connection (for example, from the internet or other untrusted networks). The key risk is that the attack does not require authentication and needs no user action. If your openFT service is not network-reachable in practice, the exposure may be lower, but reachability from the network is the deciding factor.
How urgent is it
This is urgent because the vulnerability allows remote code execution without authentication—attackers don’t need valid logins or special user interaction. Even though there’s no KEV listing or public exploit code recorded in the findings, you should still treat it as a high-risk patching issue given the potential impact of a successful attack. Verdict: AMBER.
What to do — in detail
Confirm exposure (inventory + reachability)
Identify whether you use Fujitsu Software openFT on Linux and/or Oracle Solaris.
Record the exact openFT version installed.
Check whether the openFT service is reachable from outside your trusted network (internet-facing, DMZ, partner networks, or any untrusted network). If you can connect to the service from a non-trusted host, treat it as reachable.
Determine whether you’re vulnerable
The vulnerability affects Fujitsu Software openFT for Linux and Oracle Solaris before version 12.1D00.
If your version is earlier than 12.1D00, you should consider the server vulnerable.
Upgrade to the fixed version
Linux openFT: upgrade to 12.1D00 (or later).
Oracle Solaris openFT: upgrade to 12.1D00 (or later).
If you have multiple environments (dev/test/prod), upgrade them in a controlled order starting with non-production only if your business allows; otherwise prioritize production.
Verify after patching
Confirm openFT starts successfully and core file-exchange workflows work.
Re-check network controls: ensure only required ports are open and restricted to approved IPs/networks if possible.
If you cannot upgrade immediately (temporary containment)
Restrict network access to openFT so it is not reachable from untrusted networks.
Allow only specific trusted source IPs/subnets that truly need to use openFT.
Monitor access attempts and unusual behavior around openFT endpoints/services (exact logging details depend on your openFT deployment).
Technical context
CVE-2026-16606 is a pre-auth (no authentication required) remote code execution vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT. The weakness is consistent with CWE-94 (code injection-style issues leading to arbitrary code execution). The findings state an attacker can execute arbitrary code remotely over the network with no authentication and no user interaction.
Exposure prerequisites beyond “network-reachable” are not specified in the findings (“reachable in default config: unknown” and “preconditions: unknown”), so the practical gating factor is whether the openFT service is reachable from the network.
KEV: not listed in CISA KEV. Exploit maturity: no public exploit code on record in the provided findings. EPSS is available as a prediction, but it is not included in owner-facing blocks because the findings provided do not indicate KEV/news-confirmed exploitation.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.