<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Iron Mountain - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/iron-mountain/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:20:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/iron-mountain/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in Iron Mountain enVision</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86595/</link><pubDate>Mon, 28 Sep 2026 16:20:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86595/</guid><description>CVE-2026-86595 is an SQL injection vulnerability in Iron Mountain enVision versions prior to 260655 that allows unauthenticated attackers to execute arbitrary SQL commands against the backend database.</description><content:encoded><![CDATA[<p>CVE-2026-86595 describes an SQL injection (SQLi) vulnerability affecting Iron Mountain enVision services. The vulnerability is caused by improper neutralization of special elements within SQL queries, which allows an attacker to inject arbitrary SQL commands. This flaw can be exploited by an unauthenticated remote attacker to gain unauthorized access to the underlying database, potentially resulting in data exfiltration, modification, or deletion. The vulnerability affects all versions of enVision prior to 260655. Defenders should identify all internet-facing instances of enVision and apply the vendor-provided security updates to mitigate the risk of exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized access to sensitive archived data managed by the enVision platform. Depending on the database permissions and configuration, an attacker could potentially extract the entire contents of the database, modify stored records, or gain deeper access into the hosting environment. Organizations relying on enVision for regulatory compliance or long-term data storage face significant risk of data breach and integrity loss if this flaw is exploited.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate patching of all deployed instances of enVision. Upgrade the application to version 260655 or the latest available version provided by Iron Mountain. Monitor web application firewall (WAF) logs for suspicious SQL injection patterns, such as the presence of common SQL keywords (e.g., UNION, SELECT, OR 1=1) within URI parameters or request headers directed at enVision services. Given the nature of SQLi, auditing database access logs for unusual queries originating from the application service account is also recommended to detect potential post-exploitation activity.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>sqli</category></item></channel></rss>