
OpenCTI patches notifier-template EJS injection enabling RCE
CVE-2026-39980 discloses a Critical OpenCTI template-sanitization flaw affecting `opencti < 6.9.5`, where users with Manage customization can execute arbitrary JavaScript during notifier template execution.
NewsWeb SecurityPlatform Security
1 minYesterday
