CERT-FR flags Mattermost Server vulnerabilities
CERT-FR advisory details multiple Mattermost Server flaws enabling remote denial of service and data confidentiality breaches.
CERT-FR published an advisory covering multiple vulnerabilities in Mattermost Server, an open-source collaboration and messaging platform. The flaws affect Mattermost Server versions 11.7.x prior to 11.7.11, 11.8.x prior to 11.8.6, 11.9.x prior to 11.9.2, and 11.10.x prior to 11.10.2. Successful exploitation could allow an attacker to cause a remote denial of service or compromise the confidentiality of data handled by the platform.
The advisory references three Mattermost security bulletins (MMSA-2026-00771, MMSA-2026-00775, MMSA-2026-00776) published on 22 September 2026, along with three associated CVEs (CVE-2026-95666, CVE-2026-96259, CVE-2026-96260). No details on active exploitation in the wild are provided. CERT-FR recommends administrators consult the vendor's security bulletins and apply the corresponding patches to remediate the identified issues.
Defenders running self-hosted Mattermost Server instances should prioritize upgrading to the fixed versions (11.7.11, 11.8.6, 11.9.2, or 11.10.2 and later) as soon as feasible, particularly given the confidentiality impact could expose sensitive communications data.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1212
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free