SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-35146

MEDIUM · CVSS 6.3 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

HCL DFXServer is vulnerable due to its allowance for unencrypted communication over HTTP, enabling remote attackers to intercept and potentially exploit sensitive data transmitted between users and the application. Organizations utilizing this software should prioritize addressing this vulnerability to protect against data exposure risks. This is particularly critical for environments handling sensitive information or operating in regulated industries.

CVE
CVE-2026-35146
Severity
MEDIUM
CVSS
6.3
EPSS
0.12%

Original NVD Description

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)