Critical 9.8 CVSS Flaws Hit ArcGIS Infrastructure
ID: 6d664db2-69f7-547c-a4ca-ca79cab43fb6
STIX ID: report--6d664db2-69f7-547c-a4ca-ca79cab43fb6
Feed Name: securityonline.info
Esri issued an urgent bulletin for two critical ArcGIS vulnerabilities (CVE-2026-33518 and CVE-2026-33519, CVSS 9.8) that can allow creation of over‑scoped developer credentials and improper authorization checks in Portal for ArcGIS (affecting 11.4, 11.5, and 12.0). ArcGIS Online and Location Platform were patched on April 13, 2026; Portal patches are high priority and include a proactive reset of potentially over‑scoped credentials for certain versions. Administrators should check Organization settings → Security → Developer Credentials, invalidate developer credentials if they cannot immediately patch, and apply the provided Windows, Linux, or Kubernetes updates as applicable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
