Nextcloud Server patches remote code execution flaw
A remote code execution vulnerability affects multiple Nextcloud Server and Enterprise versions; patches are available and no in-the-wild exploitation is reported.
CERT-FR has issued an advisory covering a remote code execution vulnerability in Nextcloud Server, affecting a wide range of releases from the 22.x branch through 34.0.x for both Nextcloud Community and Nextcloud Enterprise editions. The vulnerability, tracked via Nextcloud's own security advisory GHSA-7hwf-8pcj-33h4 (published 17 September 2026), allows an attacker to achieve arbitrary code execution on affected instances, though the advisory does not detail the exploitation vector or preconditions.
The advisory lists fixed versions for each affected branch (e.g., 22.2.10.42, 23.0.12.38, up through 34.0.2), indicating the vendor has released patches across all currently supported release lines. No proof-of-concept exploit or evidence of active exploitation is mentioned in the bulletin. Defenders running self-hosted Nextcloud Server or Nextcloud Enterprise should identify their deployed version against the affected ranges and apply the vendor-supplied update promptly, given the severity of remote code execution and the breadth of versions impacted.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1198
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free