OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-67105

HIGH · CVSS 7.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

HCL BigFix Service Management is vulnerable due to an insecure communication flaw that permits attackers with internal network access to intercept unencrypted HTTP traffic between backend services. This could lead to the extraction of sensitive data and facilitate man-in-the-middle (MitM) attacks. Organizations using this service should prioritize remediation to safeguard against potential data breaches and unauthorized access.

CVE
CVE-2026-67105
Severity
HIGH
CVSS
7.4
EPSS
0.15%

Original NVD Description

HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)