Description
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
Published: 2026-07-22
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT before version 12.1D00. It permits attackers without authentication to execute arbitrary code, resulting in full system compromise. The weakness is a code injection flaw (CWE‑94).

Affected Systems

Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT products, all releases prior to 12.1D00. These include the standard Linux distribution and the Oracle Solaris implementation of openFT.

Risk and Exploitability

The CVSS score of 9.3 marks this as a critical vulnerability with high potential impact. EPSS Score of < 1% indicates a very low exploitation probability. The likely attack vector is remote network access to the openFT service, and an attacker can trigger arbitrary code execution by crafting a malicious request. Owing to its pre‑authentication nature, the vulnerability can be exploited without any user interaction, making it a top‑priority for remediation.

Generated by OpenCVE AI on August 3, 2026 at 23:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fujitsu Linux openFT to version 12.1D00 or newer.
  • Upgrade Fujitsu Oracle Solaris openFT to version 12.1D00 or newer.
  • If upgrading is not immediately feasible, isolate the openFT service by restricting inbound traffic to trusted IP addresses only and applying strict firewall rules.
  • Enable logging and continuously monitor for anomalous activity around the openFT service to detect potential exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
Title Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
First Time appeared Fujitsu
Fujitsu linux Openft
Fujitsu oracle Solaris Openft
Weaknesses CWE-94
CPEs cpe:2.3:a:fujitsu:linux_openft:*:*:linux:*:*:*:*:*
cpe:2.3:a:fujitsu:linux_openft:12.1d00:*:linux:*:*:*:*:*
cpe:2.3:a:fujitsu:oracle_solaris_openft:*:*:oracle_solaris:*:*:*:*:*
cpe:2.3:a:fujitsu:oracle_solaris_openft:12.1d00:*:oracle_solaris:*:*:*:*:*
Vendors & Products Fujitsu
Fujitsu linux Openft
Fujitsu oracle Solaris Openft
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Fujitsu Linux Openft Oracle Solaris Openft
cve-icon MITRE

Status: PUBLISHED

Assigner: FTI

Published:

Updated: 2026-07-22T18:50:25.615Z

Reserved: 2026-07-22T14:31:08.591Z

Link: CVE-2026-16606

cve-icon Vulnrichment

Updated: 2026-07-22T18:50:22.296Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T16:17:16.800

Modified: 2026-07-22T20:52:35.747

Link: CVE-2026-16606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')