Skip to content
Exploit Published for Fresh Cleo Harmony Vulnerability

Exploit Published for Fresh Cleo Harmony Vulnerability

Securityweek September 2, 2026

Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony.

Tracked as CVE-2026-84115 , the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation.

The flaw was discovered in an unknown function in the file ‘/api/connections’. An attacker could craft a malicious payload that tampers with the arguments in HTTP headers, bypassing access controls and leading to privilege escalation.

According to VulnDB, an exploit targeting the bug has been released, which significantly increases the risk of exploitation against all organizations that use Cleo Harmony.

“The exploitation strategy typically involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is bypassed through malformed or replayed bearer tokens,” VulnDB notes .

Attackers could exploit the issue to maintain persistent access, elevate their privileges, or move laterally to other systems that Cleo Harmony integrates with, it says.

The vulnerability was addressed in Cleo Harmony version 5.8.1.11, but Cleo refrained from sharing any details on the security defect in its advisory .

Cleo Harmony customers should update their instances as soon as possible. As attack surface management firm WatchTowr notes, the application is “a favorite ransomware gang target”.

In late 2024, the Cl0p ransomware group exploited a Cleo product vulnerability to steal data from major organizations.

“We’ve already reproduced the vulnerability,” WatchTowr said on Tuesday, urging rapid reaction.

Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities

Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

Related: Hackers Start Exploiting Critical Langflow Vulnerability

Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Hackers Start Exploiting Critical Langflow Vulnerability

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

WatchGuard Patches Critical Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

PaperCut Exploitation Escalates to Active Intrusions

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.