Skip to content
COOEY

FAIL › dossier

ESRI

COMPANY FEDRAMP MARKET

FedRAMP provider ·

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-07-06 CVE-2026-9182 medium ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.
2026-07-07 CVE-2026-13020 high A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators sh
FEDRAMP CATALOG PRODUCTS · 3
PRODUCTSTATUSIMPACT
ArcGIS Online (AGO)AuthorizedLI-SaaS
ArcGIS Online (AGO) ModerateIn ProcessModerate
Esri Managed Cloud Services Advanced PlusAuthorizedModerate