Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · hcltech

hcltech

· 17 Critical

Total CVEs

422

Critical

17

Products

94

Search All CVEs →

422

Products (94)

bigfix platform33 CVEsdryice myxalytics31 CVEsaion29 CVEsdomino23 CVEsconnections22 CVEsbigfix service management18 CVEsaftermarket cloud17 CVEsunica17 CVEssametime17 CVEsdigital experience11 CVEsnotes11 CVEshcl leap11 CVEsbigfix mobile10 CVEsintelliops event management9 CVEsdomino leap9 CVEsbigfix compliance9 CVEsdryice mycloud9 CVEsappscan8 CVEshcl inotes7 CVEsbigfix webui7 CVEstraveler6 CVEsbigfix modern client management6 CVEsdryice iautomate6 CVEsverse5 CVEsdevops plan5 CVEsbigfix insights for vulnerability remediation5 CVEstraveler for microsoft outlook5 CVEsicontrol5 CVEsdfxanalytics5 CVEshcl compass4 CVEsdryice aex4 CVEsbigfix saas4 CVEshcl digital experience4 CVEsnomad server on domino4 CVEsbigfix osd bare metal server3 CVEsappscan source3 CVEsbigfix webui insights3 CVEsdevops velocity3 CVEsdigital experience compose3 CVEshcl nomad3 CVEshcl sx3 CVEstraveler companion3 CVEsunica centralized offer management3 CVEsversionvault express3 CVEsbigfix webui custom2 CVEsbigfix webui profile management2 CVEsbigfix webui permissions and preferences2 CVEsbigfix webui framework2 CVEsbigfix webui extensions2 CVEsbigfix webui data sync2 CVEshcl domino2 CVEsbigfix webui content app2 CVEsbigfix webui common2 CVEshcl sametime2 CVEsbigfix webui cmep2 CVEsbigfix webui application administration2 CVEsmarketing campaign2 CVEsmodern client management2 CVEsbigfix webui api2 CVEsbigfix inventory2 CVEstraveler to do2 CVEsworkload automation2 CVEsbigfix webui scm2 CVEsbigfix webui software distribution2 CVEsbigfix webui take action2 CVEsbigfix webui reports2 CVEsconnections docs2 CVEsbigfix webui query2 CVEsbigfix webui patch policies2 CVEsbigfix webui patch2 CVEsdragon2 CVEsbigfix webui mdm2 CVEsbigfix webui ivr2 CVEsunica journey1 CVEsunica audience central1 CVEsunica campaign1 CVEsmyxalytics1 CVEsunica centralised offer management1 CVEsbigfix servicenow data flow1 CVEsonetest server1 CVEsbigfix server automation1 CVEssametime chat and meetings1 CVEsunica interact1 CVEsself-service application1 CVEsbigfix patch management1 CVEshcl launch container image1 CVEsappscan presence1 CVEsunica plan1 CVEscommerce1 CVEsunica segment central1 CVEsunica contact central1 CVEsbigfix insights1 CVEslegacy ivr1 CVEslegacy ivr firmware1 CVEs

Recent Vulnerabilities

View all 422
CVE-2026-56609MEDIUM 4.8

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.

CVE-2026-56608LOW 3.7

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.

CVE-2026-56571LOW 3.7

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.

CVE-2026-56570LOW 3.7

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.

CVE-2026-56569MEDIUM 4.0

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

CVE-2026-56586LOW 3.1

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

CVE-2026-56585LOW 3.1

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

CVE-2026-56583LOW 3.1

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

CVE-2026-56582LOW 3.1

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

CVE-2026-56581LOW 2.6

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

CVE-2026-56580LOW 2.2

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

CVE-2026-56579LOW 3.1

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

CVE-2026-56578LOW 2.2

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

CVE-2026-56577LOW 3.1

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

CVE-2026-56587LOW 3.7

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

CVE-2026-56584LOW 3.7

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.

CVE-2023-37507HIGH 7.5

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

CVE-2023-37508MEDIUM 6.1

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

CVE-2026-4096MEDIUM 6.5

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking

CVE-2026-21837HIGH 8.8

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

CVE-2026-21826MEDIUM 6.1

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

CVE-2026-21825MEDIUM 6.1

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

CVE-2025-31985LOW 3.7

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.

CVE-2025-31973MEDIUM 4.0

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

CVE-2025-15634MEDIUM 4.3

A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.