Vulnerabilities

CISA Warns of Mitel MiCollab Vulnerabilities Exploited in Attacks

CISA says two recently disclosed path traversal vulnerabilities in the Mitel MiCollab collaboration platform have been exploited in attacks.

The US cybersecurity agency CISA on Tuesday warned that two recently disclosed vulnerabilities affecting the Mitel MiCollab enterprise collaboration platform have been exploited in attacks.

The two security defects, tracked as CVE-2024-41713 and CVE-2024-55550, are described as path traversal issues that impact versions 9.8 SP1 FP2 (9.8.1.201) and earlier of Mitel MiCollab.

CVE-2024-41713 (CVSS score of 9.8) is a critical bug that could allow unauthenticated attackers to gain access to provisioning information and to perform unauthorized administrative actions on the server.

CVE-2024-55550 (CVSS score of 2.7) is a low-severity flaw that could be exploited to access resources typically constrained to the admin access level, but does not allow file modification or privilege escalation. Authentication as an administrator is required for successful exploitation of this defect.

Mitel released patches for the critical vulnerability in October 2024, but made no mention of the low-severity one, which was disclosed in early December without a CVE identifier, when attack surface management firm WatchTowr warned that it had remained unpatched.

MiCollab version 9.8 SP2 (9.8.2.12), Mitel says in its advisory, addresses the critical-severity bug, mitigates the low-severity one, and addresses other critical- and high-severity security defects.

Advertisement. Scroll to continue reading.

In December, WatchTowr published technical information on both vulnerabilities and proof-of-concept (PoC) exploit code that combines them for data exfiltration, but made no mention of any of them being exploited in the wild.

On Tuesday, however, CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, warning that they have been exploited and urging federal agencies to apply the available patches and mitigations by January 28, as mandated by Binding Operational Directive (BOD) 22-01.

There does not appear to be any public information on the attacks involving exploitation of CVE-2024-41713 and CVE-2024-55550.

While BOD 22-01 only applies to federal agencies, all organizations are advised to identify vulnerable Mitel MiCollab instances within their environments and to update or remove them as soon as possible, to mitigate the risk of compromise.

Related: IBM Patches RCE Vulnerabilities in Data Virtualization Manager, Security SOAR

Related: VMware Patches High-Severity Vulnerabilities in Aria Operations

Related: White House Addresses BGP Vulnerabilities in New Internet Routing Security Roadmap

Related: Philippine Military Ordered to Stop Using Artificial Intelligence Apps Due to Security Risks

Related Content

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

Vulnerabilities

The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

Vulnerabilities

The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Vulnerabilities

The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. 

Artificial Intelligence

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version