Multiple critical vulnerabilities in ESRI ArcGIS allow an unauthenticated remote attacker to bypass security restrictions or gain user privileges. The CVSS Base Score for these vulnerabilities is 9.8 (Critical). Affected systems are all ESRI ArcGIS versions prior to the 2026 Update 2 Patch released on July 7, 2026, which contains the necessary mitigation.
[WID-SEC-2026-2237] ESRI ArcGIS: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 07.07.2026 Stand 08.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Windows Produktbeschreibung ArcGIS ist ein Geoinformationssystem. Produkte 07.07.2026 ESRI ArcGIS <2026 Update 2 Patch Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in ESRI ArcGIS ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Nutzerrechte zu erlangen. CVE Informationen Versionshistorie Feedback zum Advisory geben