# Mitel MiCollab, OpenScape UC flaws patched

Published: 2026-07-23 · Severity: medium · Sectors: telecommunications
Canonical: https://vorant.io/reports/174878ca-688a-5533-addf-e587a3125747/mitel-micollab-openscape-uc-flaws-patched

> Mitel patched multiple vulnerabilities in MiCollab and OpenScape UC that allow remote code execution and reflected XSS.

CERT-FR issued an advisory covering multiple vulnerabilities affecting Mitel MiCollab (versions prior to 10.2 SP1 FP2, 10.3.0.18, and 9.8 SP3 FP2) and OpenScape UC (versions prior to V10 R6 FR18 and V11 R1 FR2). The flaws allow an attacker to achieve remote arbitrary code execution and indirect remote code injection via cross-site scripting (XSS).

No evidence of active exploitation is mentioned in the advisory. Mitel has published fixes in security bulletins MISA-2026-0006 and MISA-2026-0007, and affected organizations are advised to apply the vendor patches referenced in the documentation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0006, CVE-2026-0007

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0911

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/174878ca-688a-5533-addf-e587a3125747/mitel-micollab-openscape-uc-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
