logo

Critical ArcGIS Account Recovery Targeted in Active Attacks

ID: 66d5c81f-34f8-583e-bcd4-c636ca02a38d

STIX ID: report--66d5c81f-34f8-583e-bcd4-c636ca02a38d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: Do Son

...
...

SecurityOnline.info reports that cybercriminals are actively exploiting ArcGIS Account Recovery workflows by targeting enabled built-in accounts and weak recovery questions to bypass MFA and obtain full account control; Esri confirms current targeted attempts and recommends administrators disable built-in Portal and Server accounts, ensure strong recovery configurations, implement SMTP for password resets, and prepare for an imminent vendor patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.