We found a Claris FileMaker Server heap buffer overflow (CVE-2026-86926)

A 2-byte block size field in an .fmp12 file header is not bound-checked, so a crafted database overflows the page buffer by 27 bytes and can reach arbitrary code execution.

Upgrade to FileMaker Server 26.0.3 or later and treat untrusted .fmp12 files as executable input.