SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-56587

LOW · CVSS 3.7 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

HCL IEM is vulnerable due to the lack of enforced Strict Transport Security, which could allow attackers to execute SSL stripping or man-in-the-middle attacks, compromising the integrity of secure communications. Organizations using HCL IEM should prioritize addressing this vulnerability to protect sensitive data and maintain secure connections. Although the severity is rated low, the potential for exploitation warrants attention, especially in environments handling confidential information.

CVE
CVE-2026-56587
Severity
LOW
CVSS
3.7
EPSS
0.15%

Original NVD Description

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

Related CVEs

Other vulnerabilities affecting the same vendor(s)