Mehrere Schwachstellen (CVE-2022-25912, CVE-2026-39920, CVE-2026-6951) in Bridgehead
Bridgehead Software - Filestore - CRITICAL - CVE-2026-39920.
BridgeHead FileStore versions prior to 24A are vulnerable due to the exposure of the Apache Axis2 administration module on network-accessible endpoints using default credentials. This allows unauthenticated attackers to gain access to the admin console, upload malicious Java archives as web services, and execute arbitrary commands on the host system through SOAP requests. Organizations using affected versions must update to version 24A to mitigate the risk of exploitation.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io