Mattermost Desktop App patches multiple flaws
Mattermost Desktop App versions before 6.2.3 contain multiple vulnerabilities that can expose data confidentiality, patches available.
ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in the Mattermost Desktop App affecting versions prior to 6.2.3. The flaws can lead to a breach of data confidentiality and an additional security issue not further specified by the vendor. Mattermost published four security bulletins (MMSA-2026-00698, 00699, 00716, 00717) on 17 August 2026 detailing the fixes, with one tracked vulnerability assigned CVE-2026-75587.
There is no indication in the advisory of active exploitation in the wild; this is a routine vendor patch notice distributed by the French national CERT. Organizations using Mattermost Desktop App should update to version 6.2.3 or later as recommended in the vendor's security updates page to mitigate potential confidentiality risks.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1040
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free