Security News

New Cleo Harmony Vulnerability: Exploit Code Now Public

Security Week · 2 Sept 2026
Key Takeaway If your business uses Cleo Harmony or similar file transfer software, check for and apply the latest security patches immediately, and monitor for unusual authentication activity.

A security vulnerability has been identified in Cleo Harmony, a widely used managed file transfer platform, that allows remote attackers to bypass authentication controls through manipulation of an authentication mechanism known as 'argument bearer' handling. Exploit code for this flaw has now been published, meaning attackers no longer need deep technical expertise to attempt to exploit it.

Cleo's file transfer products have previously been targeted in real-world attacks, including incidents linked to data theft and ransomware operations. Because authentication bypass vulnerabilities can allow attackers to gain unauthorised access to systems without needing valid credentials, this flaw is particularly concerning for any organisation using Cleo Harmony to move sensitive files between business partners, customers, or internal systems.

Businesses using Cleo Harmony should treat this as an urgent issue. Vendors typically release patches once such vulnerabilities are disclosed, and applying updates promptly is the most effective way to close the gap before attackers exploit it further. Given the public availability of exploit code, the window between disclosure and active exploitation is likely to be short.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.