Sceawere

Vulnerability Detail

CVE-2026-16606Updated Verified Sceawere Triage Sources: NVD / CISA KEV

openFT Remote Code Execution Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
5h ago
Vendor
Fujitsu
Product
Linux openFT
Attack Type
CWE-94
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-22T16:17:16.800Z",
  "pubdate": "2026-07-22T16:17:16.800Z",
  "executiveSummary": "A critical remote code execution vulnerability exists in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT. The flaw allows unauthenticated remote attackers to achieve arbitrary code execution on targeted systems running vulnerable software versions prior to 12.1D00. This security deficiency presents a severe risk to organizational infrastructure, as it enables unauthorized external entities to compromise the confidentiality, integrity, and availability of host operating systems without requiring prior credentials or administrative privileges. The vulnerability stems from improper handling of remote requests within the affected openFT service implementation, permitting malicious payloads to be injected and executed directly in the context of the running application. Exploitation requires network accessibility to the vulnerable openFT service running on GNU/Linux or Oracle Solaris platforms. The discovery and dissemination of this intelligence were managed internally by Fsas Technologies PSIRT under existing agreements with Fujitsu Germany, extending coverage beyond standard CNA scope to ensure awareness and mitigation across deployments.",
  "technicalDetails": "The vulnerability resides in the core network communication and request processing components of Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT prior to version 12.1D00. Specifically, the flaw enables unauthenticated remote code execution (pre-auth RCE) by failing to adequately validate, sanitize, or restrict incoming network data packets processed by the openFT daemon or underlying service handlers. The attack flow initiates when an unauthenticated remote attacker transmits a specially crafted network payload directly to the listening port associated with the openFT service on a targeted GNU/Linux or Oracle Solaris host. Due to insufficient input filtering and insecure deserialization or parsing logic within the vulnerable component, the malicious payload bypasses authentication mechanisms entirely. Upon reception, the openFT service processes the untrustworthy input, leading to memory corruption, insecure function execution, or direct command injection depending on the internal architecture of the flaw. Because the openFT service typically operates with elevated system privileges to perform file transfers and systems management tasks, the execution of arbitrary code results in immediate system compromise at the privilege level of the daemon. Post-exploitation activities are virtually unlimited, allowing attackers to establish persistent access, deploy additional malware, exfiltrate sensitive data, or pivot deeper into the internal network infrastructure. Mitigation requires updating the affected software to version 12.1D00 or later, where the underlying input validation and authentication checks are enforced to prevent unauthenticated remote interaction."
}
CVE-2026-16606: openFT Remote Code Execution Vulnerability (CRITICAL Severity, CVSS: 9.8) - Sceawere