logo

Critical 9.8 CVSS Flaws Hit ArcGIS Infrastructure

ID: 6d664db2-69f7-547c-a4ca-ca79cab43fb6

STIX ID: report--6d664db2-69f7-547c-a4ca-ca79cab43fb6

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

Esri issued an urgent bulletin for two critical ArcGIS vulnerabilities (CVE-2026-33518 and CVE-2026-33519, CVSS 9.8) that can allow creation of over‑scoped developer credentials and improper authorization checks in Portal for ArcGIS (affecting 11.4, 11.5, and 12.0). ArcGIS Online and Location Platform were patched on April 13, 2026; Portal patches are high priority and include a proactive reset of potentially over‑scoped credentials for certain versions. Administrators should check Organization settings → Security → Developer Credentials, invalidate developer credentials if they cannot immediately patch, and apply the provided Windows, Linux, or Kubernetes updates as applicable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.