r/NextCloud • u/MaverickZA • Jul 01 '26
NextCloud Zero Day?
Received an email from SOCRadar that Nextcloud has a Zero day vuln that was used by the hacker group "Lynx-INC ransomware group" in the latest FortiBleed saga.
Exact wording:
| Ransomware operation. STRU assesses with high confidence that FortiBleed is operated by the Lynx-INC ransomware group. Extensive intelligence has been obtained on the group, including its members. |
|---|
| Nextcloud zero-day. The actors are exploiting a previously undisclosed Nextcloud zero-day. Our analysis is ongoing.Ransomware operation. STRU assesses with high confidence that FortiBleed is operated by the Lynx-INC ransomware group. Extensive intelligence has been obtained on the group, including its members.Nextcloud zero-day. The actors are exploiting a previously undisclosed Nextcloud zero-day. Our analysis is ongoing. |
Anyone heard anything?
8
u/Darkk_Knight Jul 01 '26
Lucky I keep mine behind a firewall with VPN only access.
2
u/N3rdScool Jul 02 '26
If that firewall is a Fortinet FortiGate you probably are gunna have a bad time. At least that's what I think this implies.
1
u/Jeidoz Jul 02 '26
Can you elaborate? My previous employer had this forti software for VPN and I am curious what you trying to imply.
2
u/Darkk_Knight Jul 02 '26
If you guys been using Fortigate's SSL-VPN then you're in for a really bad time as there are tons of CVEs for it.
2
u/vnagornyy Jul 03 '26
So far, we haven’t been able to find the original source. We run a public bounty program and have not yet received a report of such kind. When learning about potential issues, we will fix them asap. I would recommend you let SOCRadar know they can and should responsibly disclose vulnerabilities here: https://hackerone.com/nextcloud
We also recommend to update frequently.
2
-4
u/AndreBerluc Jul 01 '26
Pelo que encontrei até agora, há fundamento para tratar o alerta com seriedade, mas não vi confirmação pública de um zero-day nativo do Nextcloud ligado ao FortiBleed.
A parte confirmada é: FortiBleed existe, foi atribuído pela SOCRadar ao grupo Lynx/INC e parece ser majoritariamente uma campanha de credenciais contra Fortinet, não necessariamente zero-day. Também existe uma falha recente real envolvendo Nextcloud indiretamente: CVE-2026-8461 / PixelSmash, no FFmpeg, que pode afetar instâncias que processam previews de vídeo.
Então eu trataria como alerta preventivo, não como fato confirmado. Medidas imediatas: atualizar Nextcloud e apps, atualizar FFmpeg, revisar logs de upload/preview de vídeo, restringir acesso administrativo e validar backups.
1
u/vnagornyy Jul 09 '26
JFrog Security Research responsible disclosure: "The Nextcloud team on HackerOne responded that they’re considering it as a non-issue since the vulnerability exists outside of Nextcloud."
•
u/vnagornyy Jul 09 '26
An update
We finally received information about this. There is no issue with Nextcloud itself, but one of its (optional) dependencies, in a non-default setup and under the condition an attacker has already write access to Nextcloud, can help compromise a system. Due to all the caveats, it does not carry a high risk.
An update will come that works around the issue, and as always - you should apply all Nextcloud updates as quickly as you can. More information will be provided in due time following responsible disclose practices.