# CERT-FR flags Mattermost Server vulnerabilities

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/95d121e0-97a0-5a35-b602-38dab9e41759/cert-fr-flags-mattermost-server-vulnerabilities

> CERT-FR advisory details multiple Mattermost Server flaws enabling remote denial of service and data confidentiality breaches.

CERT-FR published an advisory covering multiple vulnerabilities in Mattermost Server, an open-source collaboration and messaging platform. The flaws affect Mattermost Server versions 11.7.x prior to 11.7.11, 11.8.x prior to 11.8.6, 11.9.x prior to 11.9.2, and 11.10.x prior to 11.10.2. Successful exploitation could allow an attacker to cause a remote denial of service or compromise the confidentiality of data handled by the platform.

The advisory references three Mattermost security bulletins (MMSA-2026-00771, MMSA-2026-00775, MMSA-2026-00776) published on 22 September 2026, along with three associated CVEs (CVE-2026-95666, CVE-2026-96259, CVE-2026-96260). No details on active exploitation in the wild are provided. CERT-FR recommends administrators consult the vendor's security bulletins and apply the corresponding patches to remediate the identified issues.

Defenders running self-hosted Mattermost Server instances should prioritize upgrading to the fixed versions (11.7.11, 11.8.6, 11.9.2, or 11.10.2 and later) as soon as feasible, particularly given the confidentiality impact could expose sensitive communications data.

## Mentioned in this report

- Vulnerabilities: CVE-2026-95666, CVE-2026-96259, CVE-2026-96260

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1212

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/95d121e0-97a0-5a35-b602-38dab9e41759/cert-fr-flags-mattermost-server-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
