ArcGIS Blog

Administration

ArcGIS Trust Center

Portal for ArcGIS Security 2025 Update 1 Patch

By Mark Bierman and Randall Williams and Michael Young

On September 24, 2025, The Portal for ArcGIS Security 2025 Update 1 Patch was made obsolete. The download page has been updated to indicate the change, and users will no longer see Update 1 available in the Patch Notification tool. The URL for the obsolete patch is:

 

https://support.esri.com/en-us/patches-updates/2025/portal-for-arcgis-security-2025-update-1-patch

 

 

Vulnerabilities that where fixed by this patch.  Now fixed in Portal for ArcGIS Security 2025 Update 3 Patch

 

Password Recovery Exploitation

  • CVE Details: CVE-2025-2538
  • CWE-798 Use of Hard-coded Credentials
  • Base CVSS 3.1: 9.8 Temporal CVSS: 8.8
  • Base CVSS 4.0: 9.3

Share this article