CVE-2026-16606
Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
| CWE | CWE-94 |
| Vendor | fujitsu |
| Product | linux openft |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for fujitsu linux openft
Be the first to know when new critical vulnerabilities affecting fujitsu linux openft are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Fujitsu / Linux openFT
0 ≤ 12.1C96
Fujitsu / Oracle Solaris openFT
0 ≤ 12.1C95
References
security.eu.fsastech.com: https://security.eu.fsastech.com/IndexDownload.asp?SoftwareGuid=20873292-0006-4a1c-a188-3940762a0075 security.ts.fujitsu.com: https://security.ts.fujitsu.com/ProductSecurity/content/FsasTech-PSIRT-FTI-FG-2026-042411-Security-Notice.pdf global.fujitsu: https://global.fujitsu/de-de/capabilities/mainframe-solutions/bs2000-integration