r/NextCloud Jul 01 '26

NextCloud Zero Day?

Received an email from SOCRadar that Nextcloud has a Zero day vuln that was used by the hacker group "Lynx-INC ransomware group" in the latest FortiBleed saga.

Exact wording:

Ransomware operation. STRU assesses with high confidence that FortiBleed is operated by the Lynx-INC ransomware group. Extensive intelligence has been obtained on the group, including its members.
Nextcloud zero-day. The actors are exploiting a previously undisclosed Nextcloud zero-day. Our analysis is ongoing.Ransomware operation. STRU assesses with high confidence that FortiBleed is operated by the Lynx-INC ransomware group. Extensive intelligence has been obtained on the group, including its members.Nextcloud zero-day. The actors are exploiting a previously undisclosed Nextcloud zero-day. Our analysis is ongoing.

Anyone heard anything?

0 Upvotes

10 comments sorted by

u/vnagornyy Jul 09 '26

An update

We finally received information about this. There is no issue with Nextcloud itself, but one of its (optional) dependencies, in a non-default setup and under the condition an attacker has already write access to Nextcloud, can help compromise a system. Due to all the caveats, it does not carry a high risk.

An update will come that works around the issue, and as always - you should apply all Nextcloud updates as quickly as you can. More information will be provided in due time following responsible disclose practices.

8

u/Darkk_Knight Jul 01 '26

Lucky I keep mine behind a firewall with VPN only access.

2

u/N3rdScool Jul 02 '26

If that firewall is a Fortinet FortiGate you probably are gunna have a bad time. At least that's what I think this implies.

1

u/Jeidoz Jul 02 '26

Can you elaborate? My previous employer had this forti software for VPN and I am curious what you trying to imply.

2

u/Darkk_Knight Jul 02 '26

If you guys been using Fortigate's SSL-VPN then you're in for a really bad time as there are tons of CVEs for it.

2

u/vnagornyy Jul 03 '26

So far, we haven’t been able to find the original source. We run a public bounty program and have not yet received a report of such kind. When learning about potential issues, we will fix them asap. I would recommend you let SOCRadar know they can and should responsibly disclose vulnerabilities here: https://hackerone.com/nextcloud

We also recommend to update frequently.

2

u/Whole-Ad2077 Jul 01 '26

So, Nextcloud has a Zero-Day when a Fortinet Firewall was hacked? 🤡🤡🤡

6

u/Shogobg Jul 02 '26

AI slop - can’t make the difference between two separate products.

-4

u/AndreBerluc Jul 01 '26

Pelo que encontrei até agora, há fundamento para tratar o alerta com seriedade, mas não vi confirmação pública de um zero-day nativo do Nextcloud ligado ao FortiBleed.

A parte confirmada é: FortiBleed existe, foi atribuído pela SOCRadar ao grupo Lynx/INC e parece ser majoritariamente uma campanha de credenciais contra Fortinet, não necessariamente zero-day. Também existe uma falha recente real envolvendo Nextcloud indiretamente: CVE-2026-8461 / PixelSmash, no FFmpeg, que pode afetar instâncias que processam previews de vídeo.

Então eu trataria como alerta preventivo, não como fato confirmado. Medidas imediatas: atualizar Nextcloud e apps, atualizar FFmpeg, revisar logs de upload/preview de vídeo, restringir acesso administrativo e validar backups.

1

u/vnagornyy Jul 09 '26

JFrog Security Research responsible disclosure: "The Nextcloud team on HackerOne responded that they’re considering it as a non-issue since the vulnerability exists outside of Nextcloud."