Esri released emergency fixes for Portal for ArcGIS after disclosing two vulnerabilities that can let remote attackers gain unauthorized access and take over accounts in deployments on Windows, Linux, and Kubernetes. The most severe issue, CVE-2026-13019, is a missing-authentication flaw in a critical function that exposes an unprotected API and carries a CVSS 9.8 rating; CVE-2026-13020 is a weak password recovery flaw rated CVSS 8.1 that can allow an attacker to assume ownership of a user account by manipulating the recovery process. The bugs affect Portal for ArcGIS 12.1 and earlier, with the account-recovery risk especially relevant where built-in accounts are enabled.
Esri said customer environments have been targeted through ArcGIS Enterprise account recovery configurations and issued the Portal for ArcGIS Security 2026 Update 2 Patch to remediate the flaws and other vulnerabilities. The update removes recovery-question-based password resets for built-in users and requires SMTP-backed email validation for self-service recovery, while Esri also urged customers to adopt SAML or OIDC, enable MFA for administrators, and review hardening guidance. External reporting said active exploitation has been observed in targeted attacks, prompting calls for immediate patching from defenders including Germany's BSI CERT, particularly in sectors such as government, defense, utilities, and other critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Reporting on the two ArcGIS Portal vulnerabilities said active exploitation had been observed in targeted attacks and that Germany's BSI CERT urged organizations to patch immediately. The report described CVE-2026-13019 and CVE-2026-13020 as enabling unauthorized account takeover in affected Portal for ArcGIS deployments.
CVE-2026-13020 was disclosed as a weak password recovery mechanism in Portal for ArcGIS 12.1 and earlier that could let a remote unauthorized attacker assume ownership of a user account by manipulating the recovery process. Esri advised administrators to configure an email server with ArcGIS Enterprise to support secure self-service password recovery.
Esri PSIRT received CVE-2026-13019 on July 7, 2026. The vulnerability is a missing-authentication flaw in Portal for ArcGIS that allows a remote unauthenticated attacker to access an unprotected API in versions earlier than 12.1.
On June 23, 2026, Esri released the Portal for ArcGIS Security 2026 Update 2 Patch to remediate the account recovery issue and additional critical and high-severity vulnerabilities in Portal for ArcGIS 12.1 and earlier. The patch removed recovery-question-based resets and required SMTP-enabled email validation for self-service password recovery.
Esri said ArcGIS Enterprise account recovery configurations, particularly those using built-in accounts, were being targeted in attempts against customer environments. The company also urged customers to use centralized identity providers, enable MFA for administrators, and review hardening guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceesri.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.