Nextcloud patches Mail and Server flaws
Nextcloud fixed two vulnerabilities in Mail and Server products that could expose data confidentiality and bypass security policy.
ANSSI (CERT-FR) issued an advisory covering two vulnerabilities affecting multiple Nextcloud products, including the Mail app (versions 3.5.x through 5.7.x) and Nextcloud Server/Enterprise (versions 32.0.x through 34.0.x). The flaws, tracked as CVE-2026-61527 and CVE-2026-61545, can allow an attacker to compromise data confidentiality and bypass security policy controls.
Nextcloud has published fixed versions addressing both issues, disclosed via GitHub security advisories GHSA-99gw-ww6p-f2rr and GHSA-vq3v-jv6f-6xp2. There is no indication in the advisory of active exploitation in the wild; administrators are advised to apply the vendor patches to affected Mail and Server deployments.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0973
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free