A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
Title Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
First Time appeared Fujitsu
Fujitsu linux Openft
Fujitsu oracle Solaris Openft
Weaknesses CWE-94
CPEs cpe:2.3:a:fujitsu:linux_openft:*:*:linux:*:*:*:*:*
cpe:2.3:a:fujitsu:linux_openft:12.1d00:*:linux:*:*:*:*:*
cpe:2.3:a:fujitsu:oracle_solaris_openft:*:*:oracle_solaris:*:*:*:*:*
cpe:2.3:a:fujitsu:oracle_solaris_openft:12.1d00:*:oracle_solaris:*:*:*:*:*
Vendors & Products Fujitsu
Fujitsu linux Openft
Fujitsu oracle Solaris Openft
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: FTI

Published:

Updated: 2026-07-22T18:50:25.615Z

Reserved: 2026-07-22T14:31:08.591Z

Link: CVE-2026-16606

cve-icon Vulnrichment

Updated: 2026-07-22T18:50:22.296Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.