{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/micollab-versions-10.2.x-ant%C3%A9rieures-%C3%A0-10.2-sp1-fp2-10.2.1.205/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MiCollab versions 10.2.x antérieures à 10.2 SP1 FP2 (10.2.1.205)","MiCollab versions 10.3.x antérieures à 10.3.0.18","MiCollab versions antérieures à 9.8 SP3 FP2 (9.8.3.203)","Openscape UC versions V10 antérieures à V10 R6 FR18","Openscape UC versions V11 antérieures à V11 R1 FR2"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","xss","mitel"],"_cs_type":"advisory","_cs_vendors":["Mitel"],"content_html":"\u003cp\u003eThe French National Agency for the Security of Information Systems (ANSSI) has published an advisory regarding multiple critical vulnerabilities discovered in Mitel's MiCollab and Openscape UC products. These security flaws allow a remote attacker to achieve arbitrary code execution (RCE) and perform indirect remote code injection, commonly known as Cross-Site Scripting (XSS). The affected versions include MiCollab versions 10.2.x prior to 10.2 SP1 FP2 (10.2.1.205), versions 10.3.x prior to 10.3.0.18, and versions prior to 9.8 SP3 FP2 (9.8.3.203). Openscape UC versions V10 prior to V10 R6 FR18 and V11 prior to V11 R1 FR2 are also impacted. These vulnerabilities pose a severe risk to organizations using the affected communications platforms, potentially leading to full system compromise or client-side attacks against users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eReconnaissance \u0026amp; Vulnerability Identification\u003c/strong\u003e: An attacker identifies publicly exposed and unpatched Mitel MiCollab or Openscape UC servers within a target organization's network perimeter.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Exploitation (RCE)\u003c/strong\u003e: The attacker crafts and sends a specially malformed HTTP request or input payload designed to trigger an arbitrary code execution vulnerability on the vulnerable server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Exploitation (XSS)\u003c/strong\u003e: Alternatively or in parallel, the attacker exploits an indirect remote code injection (XSS) vulnerability by injecting malicious client-side script into a data field or application response.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eArbitrary Code Execution\u003c/strong\u003e: The vulnerable Mitel server processes the malicious input, leading to the execution of attacker-controlled code with the privileges of the affected service or system.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eClient-Side Script Execution\u003c/strong\u003e: If the XSS vulnerability is successfully exploited, the injected script executes within the web browser of any legitimate user who subsequently accesses the compromised application.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact (RCE)\u003c/strong\u003e: Successful RCE provides the attacker with unauthorized control over the affected Mitel server, enabling actions such as deploying malware, establishing persistence, exfiltrating sensitive data, or pivoting to other systems.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact (XSS)\u003c/strong\u003e: Successful XSS allows the attacker to compromise user sessions, steal credentials, deface web content, or perform other client-side malicious actions, affecting users interacting with the vulnerable application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of these vulnerabilities can lead to severe consequences for organizations utilizing the affected Mitel products. Remote Code Execution allows attackers to gain complete control over the compromised server, potentially leading to unauthorized access to sensitive data, system disruption, installation of backdoors, or the deployment of ransomware. Cross-Site Scripting (XSS) attacks can compromise user accounts, steal session cookies, deface websites, or launch phishing attacks against users interacting with the vulnerable application. Organizations in various sectors relying on these communication platforms for their daily operations are at risk of significant operational disruption and data breaches.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefer to the Mitel security advisories and promptly apply the recommended patches to all affected MiCollab and Openscape UC instances.\u003c/li\u003e\n\u003cli\u003eBlock network connections to indicators of compromise from the iocs table at the network perimeter.\u003c/li\u003e\n\u003cli\u003eRegularly review web server logs for unusual requests or patterns associated with RCE or XSS exploitation attempts, including \u003ccode\u003ewebserver\u003c/code\u003e category logs for unusual \u003ccode\u003ecs-uri-stem\u003c/code\u003e or \u003ccode\u003ecs-uri-query\u003c/code\u003e values.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T11:54:26Z","date_published":"2026-07-23T11:54:26Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mitel-rce-xss/","summary":"Multiple vulnerabilities have been discovered in Mitel MiCollab and Openscape UC products, enabling a remote attacker to achieve arbitrary code execution and conduct indirect remote code injection (XSS), posing significant risks to affected organizations.","title":"Multiple Vulnerabilities in Mitel Products Allow Remote Code Execution and XSS","url":"https://feed.craftedsignal.io/briefs/2026-07-mitel-rce-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - MiCollab Versions 10.2.x Antérieures À 10.2 SP1 FP2 (10.2.1.205)","version":"https://jsonfeed.org/version/1.1"}