These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service. This vulnerability affects applications using the LERC library, potentially allowing remote attackers to cause denial of [truncated]
An HTML injection vulnerability exists in Esri Portal for ArcGIS versions 11.3 and prior. A remote attacker with administrative privileges can insert arbitrary HTML into an administrative API. Users of ArcGIS Enterprise 11.1 and 11.3 are encouraged to patch and upgrade to the latest long-term support release. The vulnerability allows for potential HTML injection attacks on administrative APIs, necessitati [truncated]
A stored cross-site scripting issue exists in Esri Portal for ArcGIS versions 11.5 and prior. An administratively privileged attacker could inject malicious code that may execute in a victim's browser. Users of ArcGIS Enterprise 11.1, 11.3, and 11.5 should patch, and all users are advised to upgrade to the latest long-term support release. This issue requires immediate attention from administrators and us [truncated]
CVE-2026-69229 is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. An authenticated attacker can insert arbitrary HTML into the Portal for ArcGIS Home application. Users of ArcGIS Enterprise 11.1, 11.3, 11.5, and 12.0 should patch and upgrade to the latest long-term support release. The vulnerability has a CVSS score of 5.4 and a CVSS severity of MEDIUM. Affected product [truncated]
CVE-2026-69228 is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior. This vulnerability may allow a remote, unauthenticated attacker to access a specific resource that should only be accessible by authenticated users. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Defenders responsible for Esri Portal for ArcGIS deployments, particula [truncated]
CVE-2026-69225 is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier. A remote, unauthenticated attacker may exploit this vulnerability to reflect sensitive information in an HTTP response body. This vulnerability has a CVSS score of 5.9 and a severity rating of MEDIUM. Defenders responsible for Esri Portal for ArcGIS systems should assess exposure and [truncated]
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. This vulnerability has a high severity with a CVSS score of 8.1, indicating a high priority for patching or mitigation. ArcGIS Administrators should con [truncated]
CVE-2026-13019 is a critical vulnerability in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux, and Kubernetes. The vulnerability allows a remote, unauthenticated attacker to access an unprotected API, with a CVSS score of 9.8. This vulnerability is caused by a missing authentication for a critical function in Esri Portal for ArcGIS. The vulnerability can be exploited by an attacker to a [truncated]
CVE-2026-9182 is an unrestricted file upload vulnerability in ArcGIS Server. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload. This issue has a CVSS score of 5.3 and is considered Medium severity. Administrators and users of ArcGIS Server should be aware of this vulnerability and take necess [truncated]
CVE-2026-9181 is a critical directory traversal vulnerability in ArcGIS Server. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sensitive files on the system. This issue impacts all versions of ArcGIS Server 12.0 and prior. The vulnerability has a CVSS score of 9.8, indicating a critical severity level. Organizations sh [truncated]
CVE-2026-2813 is a medium-severity issue in ArcGIS Server 11.5’s login redirection workflow. A specially crafted request can cause the browser to navigate to an unintended, untrusted site during authentication, creating a limited confidentiality risk when a user interacts with the flow. The supplied description says the impact stays within the client-side navigation logic and does not lead to server-side [truncated]
CVE-2026-2812 describes an improper authentication issue affecting ArcGIS Server 12.0 and earlier. According to the NVD record, an unauthenticated attacker can send a crafted request to an undocumented administrative endpoint and may disrupt the web-based browsing interface. The vulnerability is rated CVSS 5.3 (medium) and is mapped to CWE-287.
CVE-2026-33519 is a critical incorrect-authorization vulnerability in Esri Portal for ArcGIS. Esri’s April 2026 security bulletin and the NVD record describe a failure to correctly check permissions assigned to developer credentials. The NVD entry rates the issue CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable flaw with potential high impact to confidentiality, integrity, a [truncated]
CVE-2026-33518 is a critical vulnerability in Esri Portal for ArcGIS 11.5 on Windows and Linux. The issue is described as an incorrect privilege assignment that can allow developer credentials to end up with more privileges than expected. NVD rates the flaw as CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), so defenders should treat it as urgent even though the vendor-facing description centers on pri [truncated]