ArcGIS Blog

Administration

ArcGIS Trust Center

ArcGIS Server Security 2025 Update 2 Patch

By Mark Bierman and Randall Williams and Michael Young

This patch resolves 10 Medium severity vulnerabilities in ArcGIS Server versions 10.9.1 thru 11.5 on Windows and Linux.

This patch was released December 9th, 2025. We strongly encourage ArcGIS Enterprise customer apply this patch within the next two weeks to minimize risk.

Important Notes:

  • Cumulative – This patch is cumulative and does not require that you install any previous ArcGIS Server Security patches prior to installing this patch – Using the Patch Notification Utility can help ease this process. This patch is NOT dependent on other patches to be in place.
  • Mitigation – In order to mitigate these vulnerabilities, we strongly recommend all ArcGIS Enterprise customers install this patch as soon as possible.
  • Unaffected Versions – 12.0 is not effected by these vulnerabilities. Customers with security concerns should always maintain their deployments on the most recent release of ArcGIS Enterprise as it will always have the most up to date 3rd party libraries of any of our software versions in current support.
  • Unsupported and Mature Support StatusArcGIS Server versions prior to 10.9.1 are retired or are in mature support status. These versions should be assumed vulnerable.

 

Download the patch here.

Vulnerability Details:

 

  • CVE ID: CVE-2025-67703
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 5.8

 

  • CVE ID: CVE-2025-67704
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 5.8

 

  • CVE ID: CVE-2025-67705
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 5.8

 

  • CVE ID: CVE-2025-67706
    • CWE – CWE-434: Unrestricted Upload of File with Dangerous Type
    • CVSS v4.0 Base Score: 5.3
    • CVSS v3.1 Base Score: 5.6

 

  • CVE ID: CVE-2025-67707
    • CWE – CWE-434: Unrestricted Upload of File with Dangerous Type
    • CVSS v4.0 Base Score: 5.3
    • CVSS v3.1 Base Score: 5.6

 

  • CVE ID: CVE-2025-67708
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 5.8

 

  • CVE ID: CVE-2025-67709
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 5.8

 

  • CVE ID: CVE-2025-67710
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 5.8

 

  • CVE ID: CVE-2025-67711
    • CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)
    • CVSS 4.0: 5.3
    • CVSS 3.1: 4.8

Share this article