Multiple vulnerabilities in Mattermost Desktop App (June 18, 2026)
Multiple vulnerabilities were discovered in Mattermost Desktop App. They allow an attacker to cause remote denial of service and an unspecified security issue by the vendor.
CSIRTS triage
- What
- Remote denial of service and an unspecified security issue were discovered in Mattermost Desktop App.
- Who is affected
- Users of Mattermost Desktop App are affected, though specific versions are not stated.
- Urgency
- Moderate urgency due to denial of service capability, though severity is unknown and no active exploitation has been reported.
- Action
- Update Mattermost Desktop App to the patched version when available; check vendor advisories for specific version numbers and remediation steps.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Desktop App
Get an email when a new Desktop App advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0777/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-96020.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-80750.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9602 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8075 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Mattermost Desktop App
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Mattermost Desktop App (August 18, 2026)cert-fr-avis · 2026-08-18
- lowCVE-2026-75587: Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generati…nvd · 2026-08-17
- mediumCVE-2026-9602: Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Ma…nvd · 2026-07-17
- mediumCVE-2026-8075: Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking …nvd · 2026-07-17
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21