External risk intelligence

Fujitsu openFT Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-16606

Fujitsu openFT is a managed file transfer solution typically used within internal enterprise environments for back-end data exchange. While network-reachable, it is generally deployed behind internal security controls and is not designed to be a public-facing internet service.

Code Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Fujitsu Software's openFT, a file transfer technology used with Linux and Oracle Solaris. This issue could allow unauthenticated remote code execution, meaning an attacker could potentially run unauthorized commands on affected systems without needing any credentials. The main concern at this time is to determine if our environment utilizes this specific technology and is therefore exposed.

  • The issue allows unauthorized code execution remotely.
  • It impacts a specialized file transfer technology.
  • Confirm relevance and exposure to understand potential risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network traffic to an exposed Fujitsu openFT instance. This could allow them to execute arbitrary code on the affected system without needing any prior authentication or access.

  • Unauthenticated network access is required.
  • Specially crafted network traffic triggers the flaw.
  • Risk of unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT could allow unauthenticated remote code execution. This means an attacker could potentially run their own code on the affected system without needing any credentials, when supported by the advisory's conditions.

  • System code execution.
  • Network-based remote execution.
  • Compromise of system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

Owners of Fujitsu Software Linux openFT and Oracle Solaris openFT deployments must prioritize identifying all instances of the affected technology. Confirming network reachability and business criticality for each instance will enable accurate risk assessment and facilitate engagement with the appropriate teams, such as infrastructure or platform engineering, for planned remediation.

  • Identify affected systems and owners.
  • Verify reachability and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Fujitsu openFT?

Fujitsu openFT is a managed file transfer technology designed for reliable, automated data exchange between enterprise systems. It is commonly used in mainframe-to-server or server-to-server environments, often facilitating critical business data integration across Linux and Oracle Solaris platforms.

How does CVE-2026-16606 work?

This vulnerability falls under the Improper Control of Generation of Code class, known as CWE-94. It allows an unauthenticated remote attacker to inject and execute arbitrary commands on a target system. Because the software fails to properly validate inputs, it can be coerced into running unauthorized code, effectively granting the attacker control over the host system's operations.

Do I need authentication to trigger this bug?

No, authentication is not required to trigger this vulnerability. An attacker can initiate the exploit by sending specially crafted network traffic directly to the service. However, the flaw is not triggered by standard, legitimate file transfer requests; it specifically requires packets designed to exploit the underlying code execution weakness.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that while these instances are network-reachable, they are typically used for internal enterprise back-end data exchange. Because the technology is generally deployed behind internal security controls rather than as a public-facing internet service, the likelihood of direct external exploitation is considered low.

When should I address this vulnerability?

You should prioritize identifying all instances of Fujitsu openFT within your environment immediately. Once identified, verify which systems are running versions before 12.1D00. After cataloging these assets, engage your platform or infrastructure engineering teams to plan and schedule the necessary software updates to remove the vulnerability.

References