CVE-2026-9181Disclosure(esri / arcgis_server)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch esri arcgis_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arcgis_server
  • linux_kernel
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-19); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Products
arcgis_serverlinux_kernelwindows

1 version affected across 3 products

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-07-06: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-13: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 2Mentions · 2026-07-30: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-13: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-30: 107-0607-0807-0907-1307-1807-1907-30
Signal classification3 categories
Disclosure
337.5%
General
337.5%
Patch
225.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-061
Patch1
2026-07-081
Disclosure1
2026-07-091
Patch1
2026-07-131
Disclosure1
2026-07-181
General1
2026-07-192
Disclosure1General1
2026-07-301
General1
Full discourse8 posts
  • Horizon3.ai@Horizon3ai
    Disclosure

    🚨 An internet-facing ArcGIS Server can become an unauthenticated file disclosure point. Rapid Response test now available for CVE-2026-9181. https://t.co/8umHL3bbKF

    Post summary

    A Rapid Response test for CVE‑2026‑9181, an ArcGIS Server unauthenticated file disclosure, is now available; no exploit code or patch details are announced.

    111028142.7K
    3.0K followersView on X
  • Morty@MortyJin
    Disclosure

    CVE-2026-9181 (CVSS 9.8): unauthenticated path traversal in Esri ArcGIS Server. A single ../ in an upload filename escapes the upload dir and overwrites config-store — disable auth or swap the super-admin password for full site takeover. Patched in SEC2026U2; EOL 10.x remains exposed. Walkthrough https://rustlang.rs/posts/blog_cve_2026_9181_arcgis_en/

    Post summary

    The text discloses a high‑severity path traversal in Esri ArcGIS Server that allows full site takeover, provides a patch reference, and includes a walkthrough link for more detail.

    00001199
    164 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-9181 — CVSS 9.8/10 ██████████ ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/8xzDQ2fPBe

    Post summary

    The tweet announces a critical directory traversal flaw in ArcGIS Server (CVE‑2026‑9181, CVSS 9.8/10) and urges users to apply the patch immediately.

    10000123
    64 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-9181: ArcGIS Server Directory Traversal - What It Means for Your Business and How to Respond https://hubs.li/Q04rqzxM0

    Post summary

    An advisory article about CVE-2026-9181 that highlights a directory traversal flaw in ArcGIS Server, but provides no explicit PoC, exploit, patch, or evidence of active exploitation.

    0000040
    32 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-9181 EsriのArcGIS Serverに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/13/cve-2026-9181-arcgis-server/ #IT #Security #cybersecurity

    Post summary

    The post alerts that CVE-2026-9181 is a critical vulnerability in Esri’s ArcGIS Server, calling for immediate action, yet it offers no technical specifics or remediation guidance.

    0000054
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-9181 EsriのArcGIS Serverに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/13/cve-2026-9181-arcgis-server/ #IT #Security #cybersecurity

    Post summary

    The post alerts that CVE-2026-9181 is a serious vulnerability requiring immediate attention, but it provides no specific technical details, exploit code, patch information, or evidence of active exploitation.

    0000059
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-9181 EsriのArcGIS Serverに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/13/cve-2026-9181-arcgis-server/ #IT #Security #cybersecurity

    Post summary

    The post warns of a critical vulnerability in Esri ArcGIS Server (CVE‑2026‑9181) but offers no additional details, evidence of exploitation, patches, or proof‑of‑concept information.

    0000055
    208 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-9181 (CVSS 9.8) Esri ArcGIS Server directory traversal flaw allows unauthenticated attackers to overwrite sensitive files & gain full admin access. Affected: ArcGIS Server ≤12.0 (Windows/Linux) NOT affected: ArcGIS Enterprise on Kubernetes #CVE #PatchNow https://t.co/UITkr9PDmK

    Post summary

    The tweet announces CVE‑2026‑9181, a critical directory traversal vulnerability in Esri ArcGIS Server (≤12.0) that lets unauthenticated users overwrite files and gain admin rights, and it urges users to patch promptly.

    0000059
    70 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appesriarcgis_server---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more