AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66300

MEDIUM · CVSS 5 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The reflected XSS vulnerability in the Web Route redirection functionality of SNOMED International Snowstorm allows attackers to inject arbitrary JavaScript, potentially compromising user sessions when victims click on malicious links. Organizations using affected versions of Java should prioritize applying the security updates in versions 10.12.2 and 10.9.3 to mitigate the risk of exploitation. This vulnerability is particularly relevant for developers and security teams managing web applications that utilize this software.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66300
Severity
MEDIUM
CVSS
5
EPSS
0.18%
Java

Original NVD Description

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.