Unrated severityNVD Advisory· Published Jul 22, 2026· Updated Jul 22, 2026
Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
CVE-2026-16606
Description
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
Affected products
2- Range: <12.1D00
Patches
Vulnerability mechanics
References
3- security.eu.fsastech.com/IndexDownload.aspmitrevendor-advisory
- security.ts.fujitsu.com/ProductSecurity/content/FsasTech-PSIRT-FTI-FG-2026-042411-Security-Notice.pdfmitrevendor-advisory
- global.fujitsu/de-de/capabilities/mainframe-solutions/bs2000-integrationmitremitigation
News mentions
0No linked articles in our index yet.