Close Menu
NCIJ Network NCIJ Network
    What's Hot

    USPS Is Building a Mail-In Ballot Screening System Despite Legal Battles Over Trump Order

    September 2, 2026

    Democrats Have a Plan to Force Trump’s Associates to Cooperate With Investigations

    September 2, 2026

    Motional and MIT AI explains self-driving car decisions

    September 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • USPS Is Building a Mail-In Ballot Screening System Despite Legal Battles Over Trump Order
    • Democrats Have a Plan to Force Trump’s Associates to Cooperate With Investigations
    • Motional and MIT AI explains self-driving car decisions
    • Exploit Published for Fresh Cleo Harmony Vulnerability
    • US Officials Work with CrowdStrike to Fight Malware behind Crypto Theft
    • NASA’s Hubble Tracks New Decagon Encircling Saturn’s South Pole
    • Indigenous ‘turtle women’ help vulnerable reptiles recover in Ecuadorian Amazon
    • I inadvertently misled parliament over a British nuclear scandal. Now I’m calling for justice | Tobias Ellwood
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Exploit Published for Fresh Cleo Harmony Vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 2, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony.

    Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation.

    The flaw was discovered in an unknown function in the file ‘/api/connections’. An attacker could craft a malicious payload that tampers with the arguments in HTTP headers, bypassing access controls and leading to privilege escalation.

    According to VulnDB, an exploit targeting the bug has been released, which significantly increases the risk of exploitation against all organizations that use Cleo Harmony.

    “The exploitation strategy typically involves intercepting legitimate traffic or forging new requests where the JWT refresh token logic is bypassed through malformed or replayed bearer tokens,” VulnDB notes.

    Attackers could exploit the issue to maintain persistent access, elevate their privileges, or move laterally to other systems that Cleo Harmony integrates with, it says.

    Advertisement. Scroll to continue reading.

    The vulnerability was addressed in Cleo Harmony version 5.8.1.11, but Cleo refrained from sharing any details on the security defect in its advisory.  

    Cleo Harmony customers should update their instances as soon as possible. As attack surface management firm WatchTowr notes, the application is “a favorite ransomware gang target”.

    In late 2024, the Cl0p ransomware group exploited a Cleo product vulnerability to steal data from major organizations. 

    “We’ve already reproduced the vulnerability,” WatchTowr said on Tuesday, urging rapid reaction.

    Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities

    Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

    Related: Hackers Start Exploiting Critical Langflow Vulnerability

    Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

    Cleo exploit fresh Harmony Published Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    OpenLeash Adds a Human Check to Risky AI Agent Actions

    Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    USPS Is Building a Mail-In Ballot Screening System Despite Legal Battles Over Trump Order

    September 2, 2026

    Democrats Have a Plan to Force Trump’s Associates to Cooperate With Investigations

    September 2, 2026

    Motional and MIT AI explains self-driving car decisions

    September 2, 2026

    Exploit Published for Fresh Cleo Harmony Vulnerability

    September 2, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    USPS Is Building a Mail-In Ballot Screening System Despite Legal Battles Over Trump Order

    September 2, 2026

    Democrats Have a Plan to Force Trump’s Associates to Cooperate With Investigations

    September 2, 2026

    Motional and MIT AI explains self-driving car decisions

    September 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.