SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16606

CRITICAL · CVSS 9.8 EPSS 0.65% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Fujitsu Software's openFT versions prior to 12.1D00 on GNU/Linux and Oracle Solaris are susceptible to unauthenticated remote code execution, allowing attackers to execute arbitrary code without authentication. This critical vulnerability, rated 9.8 on the CVSS scale, poses a significant risk to systems running these affected products. Organizations utilizing these versions should prioritize immediate patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16606
Severity
CRITICAL
CVSS
9.8
EPSS
0.65%
Linux Oracle

Original NVD Description

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.