# Nextcloud patches Mail and Server flaws

Published: 2026-08-06 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/d7a66f01-d27e-5c08-b7a3-2af15f9c7236/nextcloud-patches-mail-and-server-flaws

> Nextcloud fixed two vulnerabilities in Mail and Server products that could expose data confidentiality and bypass security policy.

ANSSI (CERT-FR) issued an advisory covering two vulnerabilities affecting multiple Nextcloud products, including the Mail app (versions 3.5.x through 5.7.x) and Nextcloud Server/Enterprise (versions 32.0.x through 34.0.x). The flaws, tracked as CVE-2026-61527 and CVE-2026-61545, can allow an attacker to compromise data confidentiality and bypass security policy controls.

Nextcloud has published fixed versions addressing both issues, disclosed via GitHub security advisories GHSA-99gw-ww6p-f2rr and GHSA-vq3v-jv6f-6xp2. There is no indication in the advisory of active exploitation in the wild; administrators are advised to apply the vendor patches to affected Mail and Server deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-61527, CVE-2026-61545

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0973

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d7a66f01-d27e-5c08-b7a3-2af15f9c7236/nextcloud-patches-mail-and-server-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
