# Nextcloud Server patches remote code execution flaw

Published: 2026-09-17 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/b5a982cb-236e-5bae-a1f4-9c8cc0dc2629/nextcloud-server-patches-remote-code-execution-flaw

> A remote code execution vulnerability affects multiple Nextcloud Server and Enterprise versions; patches are available and no in-the-wild exploitation is reported.

CERT-FR has issued an advisory covering a remote code execution vulnerability in Nextcloud Server, affecting a wide range of releases from the 22.x branch through 34.0.x for both Nextcloud Community and Nextcloud Enterprise editions. The vulnerability, tracked via Nextcloud's own security advisory GHSA-7hwf-8pcj-33h4 (published 17 September 2026), allows an attacker to achieve arbitrary code execution on affected instances, though the advisory does not detail the exploitation vector or preconditions.

The advisory lists fixed versions for each affected branch (e.g., 22.2.10.42, 23.0.12.38, up through 34.0.2), indicating the vendor has released patches across all currently supported release lines. No proof-of-concept exploit or evidence of active exploitation is mentioned in the bulletin. Defenders running self-hosted Nextcloud Server or Nextcloud Enterprise should identify their deployed version against the affected ranges and apply the vendor-supplied update promptly, given the severity of remote code execution and the breadth of versions impacted.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1198

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b5a982cb-236e-5bae-a1f4-9c8cc0dc2629/nextcloud-server-patches-remote-code-execution-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
