Security Alert

 

 

Important Security Notice (13 April 2026)
Developer Credential Vulnerability in ArcGIS Online, ArcGIS Location Platform & ArcGIS Enterprise

We would like to draw your attention to the security vulnerability in Developer Credentials (API Keys) that may have granted over-scoped permissions. This issue affects users of ArcGIS Online, ArcGIS Location Platform, and ArcGIS Enterprise. While no customers have reported exploitation of this vulnerability, API keys and OAuth 2.0 credentials could potentially be exploited if not addressed.

Our support team has consolidated the key information:

ArcGIS Online and ArcGIS Location Platform
A software update will be pushed out on Monday April 13th that will update existing Developer Credentials to match the permission levels selected by the customer during creation.

ArcGIS Enterprise
A security patch has been released on April 13th. All ArcGIS Enterprise 11.4, 11.5 and 12.0 customers should apply this security patch as a high priority. Customers should apply the Portal for ArcGIS Security 2026 Update 1 Patch for ArcGIS Enterprise 11.4, 11.5 and 12.0 on Windows/Linux and apply Update 3 for ArcGIS Enterprise 12.0 on Kubernetes as described here.

For additional information and continuous updates on these vulnerabilities, please visit:

April 2026 ArcGIS Security Bulletin
ArcGIS Trust Center
Secure Best Practices: ArcGIS Developer Credentials


Latest ArcGIS Security Update (9 Oct 2025)
ArcGIS Server Feature Services Security Patch

We would like to draw your attention to a critical security patch recently released by Esri for ArcGIS Server Feature Services (versions 11.3, 11.4, and 11.5). Our support team has consolidated the key information, and we strongly recommend applying this patch immediately.

Recommended Actions:

  • Apply the critical security patch immediately

  • Upgrade ArcGIS Enterprise on Kubernetes environments from versions 11.3 or 11.4 to 11.5.

  • Follow security best practices, including the use of web application firewalls (WAF), as recommended in the latest ArcGIS Enterprise Hardening Guide.

 

For more details on this patch and other updates, please visit:

Esri Support Patches & Updates


Latest ArcGIS Security Update

We would like to draw your attention to several critical security updates recently released by Esri. Our support team has consolidated the relevant patches below, and we strongly recommend applying them as soon as possible.

In addition to these security updates, we highly recommend implementing the 2025 Critical Best Practices to further enhance system security.

 

For more patches and updates, please visit:

Esri Support Patches & Updates


Information about Best Practices when using ArcGIS Online to Share Items and Survey Form to Public Access

 

We would like to draw your attention that if an organization has need to share ArcGIS Online Items or an ArcGIS Online Survey form to the public for collecting information from your target audience, it is recommended to make reference to the following best practices to design your processing workflow to impose more control on sharing ArcGIS Online items to the public.

Learn More on best practices


Compliance Requirements on Embedded Content by Code in ArcGIS Experience Builder

 

A security patch that was recently applied to ArcGIS Experience Builder in ArcGIS Online, which will require your affected applications under subscription ID  to be changed manually.

Your ArcGIS Developer subscription account can no longer access the embed by code feature as of now. After September 28, 2023, your applications that use the embed by code feature in ArcGIS Online will no longer work. Please make changes to your applications before the patch.

See Solution


Log4Shell Vulnerability and ArcGIS Products

Important Security Update 

The Log4Shell vulnerabilities (CVE-2021-44228, CVE-2021-45046) are critical security vulnerabilities in version 2 of the Apache Log4j library. This library is widely used across many software products from many vendors, including Esri products. Esri is actively engaged on this evolving topic.

 

Esri has published a blog post on the ArcGIS Trust Center that reflects the currently available information for all ArcGIS products, including ArcGIS Online, ArcGIS Pro, and ArcGIS Enterprise. This blog is your go-to resource as Esri addresses the Log4Shell vulnerabilities, and it will be updated regularly as new information and guidelines are made available.

 

Esri recommends that all ArcGIS customers review the blog.

 

ArcGIS Enterprise Log4j Security Patches Available

 

If you have additional questions after reviewing this guidance, please contact Esri China (HK) Technical Support via support@esrichina.hk or 37685909.