VORANT. Threat Intelligence Sign in Get the full feed

Mitel MiCollab, OpenScape UC flaws patched

medium vulnerability telecommunications

Mitel patched multiple vulnerabilities in MiCollab and OpenScape UC that allow remote code execution and reflected XSS.

CERT-FR issued an advisory covering multiple vulnerabilities affecting Mitel MiCollab (versions prior to 10.2 SP1 FP2, 10.3.0.18, and 9.8 SP3 FP2) and OpenScape UC (versions prior to V10 R6 FR18 and V11 R1 FR2). The flaws allow an attacker to achieve remote arbitrary code execution and indirect remote code injection via cross-site scripting (XSS).

No evidence of active exploitation is mentioned in the advisory. Mitel has published fixes in security bulletins MISA-2026-0006 and MISA-2026-0007, and affected organizations are advised to apply the vendor patches referenced in the documentation.

Mentioned in this report

Vulnerabilities CVE-2026-0006CVE-2026-0007

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0911

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free