CVE-2026-12602Disclosure

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive permissions for the ‘Everyone’ group. This could allow an unprivileged user to replace the main executable and/or its components with a malicious file, thereby enabling the execution of arbitrary code. In the worst-case scenario, if the malicious code is executed with elevated privileges (such as those of Administrator or SYSTEM), the attacker could escalate privileges and gain full control of the system, compromising both security and data integrity.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-22); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-22: 2Mentions · 2026-06-23: 1Active Exploitation · 2026-06-23: 1Technical Details · 2026-06-22: 206-2206-23
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-222
Disclosure1General1
2026-06-231
Active Exploitation1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Aruba Sign (CVE-2026-12602) https://vuldb.com/vuln/372676/cti

    Post summary

    Offensive actors have been observed targeting Aruba Sign via CVE-2026-12602, indicating active exploitation in the wild, but no PoC, tooling, patch, or technical details are provided.

    00000105
    2.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12602 Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the … https://www.cve.org/CVERecord?id=CVE-2026-12602 ----- Traducción: CVE-2026-12602 Per… http://infoflow.cloud`

    Post summary

    The tweet reports the disclosure of CVE-2026-12602, noting incorrect default permissions in ArubaSign versions prior to v4.6.6, but does not mention exploitation, patches, or PoC details.

    0000038
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-12602 Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the … https://www.cve.org/CVERecord?id=CVE-2026-12602

    Post summary

    The post references CVE-2026-12602, noting that older ArubaSign versions have incorrect default permissions, without details on exploitation, patches, or PoC.

    00000699
    57.7K followersView on X

Explore more