By vendor

Esri vulnerabilities

Known CVEs affecting Esri products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-13020HIGH 8.1

    Esri's Portal for ArcGIS contains a flaw in how it handles forgotten password requests. An attacker can exploit this weakness to take over user accounts without authorization. The vulnerability affects Portal for ArcGIS version 12.1 and earlier on Windows, Linux, and Kubernetes deployments. Organizations running these versions should prioritize patching or implementing the recommended email server configuration to enable secure self-service password recovery.