OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-67101

CRITICAL · CVSS 9.3 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

HCL BigFix Service Management is vulnerable to a critical Server-Side Request Forgery (SSRF) flaw in its search functionality, enabling attackers to manipulate the application server into sending requests to internal systems, potentially exposing sensitive data or services. Organizations utilizing this software should prioritize remediation efforts to mitigate the risk of unauthorized access to internal network resources. Immediate action is recommended for all users to prevent potential exploitation.

CVE
CVE-2026-67101
Severity
CRITICAL
CVSS
9.3
EPSS
0.34%

Original NVD Description

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.