CVE-2026-26221Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and TimerServiceEvents.rem for Workflow) to trigger unsafe object unmarshalling, enabling arbitrary file read/write. By writing attacker-controlled content into web-accessible locations or chaining with other OnBase features, this can lead to remote code execution. The same primitive can be abused by supplying a UNC path to coerce outbound NTLM authentication (SMB coercion) to an attacker-controlled host.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-14); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-13: 1Mentions · 2026-02-14: 2Mentions · 2026-02-15: 1Active Exploitation · 2026-02-14: 1Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 102-1302-1402-15
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-131
Disclosure1
2026-02-142
Active Exploitation1Patch1
2026-02-151
Disclosure1
Full discourse4 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26221: Hyland OnBase Timer Services Una... OnBase's .NET Remoting on TCP/8900 is a perfect storm: unauthenticated deserialization to file operations, web-accessib... https://zerodaysignal.com/vulnerability/CVE-2026-26221 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-26221 is a vulnerability in Hyland OnBase’s .NET Remoting service on TCP/8900 that allows unauthenticated deserialization leading to file operations, with no PoC, exploit, or patch discussed.

    0000056
    131 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Hyland OnBase Workflow Timer Service (CVE-2026-26221) https://vuldb.com/?ctiid.345910

    Post summary

    The CTI team reports that Hyland OnBase Workflow Timer Service (CVE-2026-26221) is currently being targeted in the wild, indicating active exploitation.

    0000052
    2.1K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-26221 in Hyland OnBase 8.0 exposes unauthenticated .NET Remoting on TCP/8900. RCE & file write risk! Restrict access & monitor now. Patch ASAP when available. 🔒 https://radar.offseq.com/threat/cve-2026-26221-cwe-502-deserialization-of-untruste-9949df79 #Of... https://t.co/whmhnG5oH6

    Post summary

    The tweet warns about CVE-2026-26221 in Hyland OnBase 8.0, detailing an unauthenticated RCE risk via .NET Remoting, and urges patching as soon as a fix is available.

    0000059
    268 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Hyland OnBase Workflow Timer Service (CVE-2026-26221) https://vuldb.com/?id.345910

    Post summary

    The post announces CVE-2026-26221 affecting Hyland OnBase Workflow Timer Service, linking to a vulnerability database entry, but offers no further technical details or evidence of exploitation.

    0000048
    2.1K followersView on X

Explore more