Executive brief
Fujitsu openFT is a managed file transfer solution used to securely move data across different enterprise platforms. A critical vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the underlying Linux or Solaris operating system. This could lead to a complete system takeover, theft of sensitive files, or disruption of business-critical data transfers.
Technical details
A remote code execution vulnerability exists in Fujitsu openFT for Linux and Solaris due to improper control of generation of code (CWE-94). The flaw allows an unauthenticated attacker to execute arbitrary code with the privileges of the openFT service via network-based requests. The vulnerability is present in versions prior to 12.1D00. Successful exploitation grants the attacker full control over the affected GNU/Linux or Oracle Solaris environment. Users are advised to upgrade to version 12.1D00 or later to mitigate this risk.
Affected products
- Fujitsu Linux openFT before 12.1D00
- Fujitsu Oracle Solaris openFT before 12.1D00
Timeline
- 2026-07-20: advisory: Initial security notice issued by Fsas Technologies PSIRT
- 2026-07-22: disclosed: CVE-2026-16606 published to the NVD