VORANT. Threat Intelligence Research Sign in Create a free account

CERT-FR Flags Multiple Nextcloud Vulnerabilities

routine vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory details five CVEs in Nextcloud Server, Collectives, Team Folders and files_lock enabling privilege escalation, DoS and data exposure; patches available.

CERT-FR has published an advisory covering multiple vulnerabilities affecting the Nextcloud product suite, including Nextcloud Server (32.0.x, 33.0.x, 34.0.x), the Collectives app, the Team Folders app (multiple branches from 13.x through 22.x), and files_lock (33.0.x). The flaws, tracked under five CVEs (CVE-2026-68493, CVE-2026-77165, CVE-2026-77166, CVE-2026-77169, CVE-2026-82985) and corresponding GitHub security advisories, can allow an attacker to escalate privileges, cause a remote denial of service, bypass security policy, or access confidential data depending on the specific flaw and affected component.

No evidence of in-the-wild exploitation is mentioned in the advisory. CERT-FR directs administrators to the Nextcloud vendor bulletins for patch details and recommends upgrading to the fixed versions: Collectives 4.4.1+, files_lock 33.0.6+, Server 32.0.12+/33.0.6+/34.0.1+, and the various Team Folders branch fixes (ranging from 13.1.8 to 22.0.1 depending on branch).

Defenders running self-hosted Nextcloud instances, particularly those exposing collaborative file-sharing and team folder features, should prioritize patching to the versions specified, as the vulnerabilities span confidentiality, integrity (policy bypass), and availability impacts across core and plugin components.

Mentioned in this report

Vulnerabilities CVE-2026-68493CVE-2026-77165CVE-2026-77166CVE-2026-77169CVE-2026-82985

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1283

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,164 reports from 148 sources, 494 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs