ArcGIS Blog

Administration

ArcGIS Trust Center

September 2026 ArcGIS Security Bulletin

By Mark Bierman and Randall Williams and Michael Young

The Portal for ArcGIS 2026 Security Update 4 patch has been released and is available here.

This patch resolves one medium and two critical severity security vulnerabilities in Portal for ArcGIS versions 12.1 and earlier.

This patch was released September 24th, 2026. We strongly encourage ArcGIS Enterprise customers apply this patch ASAP to minimize risk.

Patch Notes:

  • Cumulative – This patch is cumulative and does not require that you install any previous Portal for ArcGIS Security patches prior to installing this patch – Using the Patch Notification Utility can help ease this process. This patch is NOT dependent on other patches to be in place.
  • Esri has reserved CVE identifiers for the vulnerabilities fixed in this patch.
  • Mitigation – In order to mitigate these vulnerabilities, we strongly recommend all ArcGIS Enterprise customers install this patch as soon as possible.

Vulnerability Details 

CVE-2026-69227 :

  • CWE-306: Missing Authentication for Critical Function
  • Base CVSSv3.1: 9.8 (critical)
  • Temporal CVSSv3.1: 9.4 (critical)
  • Affected: All Portal for ArcGIS versions 12.1 and prior

CVE-2026-69226:

  • CWE-863 Incorrect Authorization
  • Base CVSSv3.1: 6.5 (medium)
  • Temporal CVSSv3.1: 6.2 (medium)
  • Affected: All Portal for ArcGIS versions 12.1 and prior

CVE-2026-10759:

  • CWE-90: Improper Neutralization of Special Elements used in an LDAP Query (‘LDAP Injection’)
  • Base CVSSv3.1: 5.5 (medium)
  • Temporal CVSSv3.1: 5.3 (medium)
  • Affected: All Portal for ArcGIS versions 12.1 and prior

Share this article