Junglewise Threat Intelligence

CVE-2026-86926: A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 data

CVE-2026-86926 · Severity: high · CVSS 7.8 · Published 2026-09-23

Executive brief

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.