VulnSea

HCL Software has 14 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 5.7 (medium), with 2 rated critical. None have a confirmed exploitation report. Most affected products: HCL BigFix Service Management (9), MyXalytics (3), HCL AppScan 360° (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.7
Publish → KEV
Last 90 days
14 prev 0

Products

  • HCL BigFix Service Management 9
  • MyXalytics 3
  • HCL AppScan 360° 1
  • HCL BigFix Service Management 1
14
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

HCL Software vulnerabilities

CVEs affecting HCL Software, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-21806Low· 3.1
3d ago

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.15%via NVD
CVE-2026-21822Medium· 6.3
3d ago

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially…

SunlitHCL Software · HCL AppScan 360°EPSS 0.21%via NVD
CVE-2026-21848Medium· 5.0
3d ago

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across…

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.20%via NVD
CVE-2026-56590Medium· 6.4
3d ago

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a compl…

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a compl…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.17%via NVD
CVE-2026-56597Low· 3.1
3d ago

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underly…

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underly…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.16%via NVD
CVE-2026-56595Low· 3.1
3d ago

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, en…

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, en…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.15%via NVD
CVE-2026-56592Medium· 6.5
3d ago

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the l…

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the l…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.25%via NVD
CVE-2026-67103High· 7.6
3d ago

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover…

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover…

TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.22%via NVD
CVE-2026-67102High· 8.1
3d ago

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.27%via NVD
CVE-2026-67101Critical· 9.3
3d ago

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.27%via NVD
CVE-2026-67100Critical· 9.8
3d ago

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well a…

MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.35%via NVD
CVE-2025-52657Low· 3.5
2w ago

HCL MyXalytics was affected by Potential DOS Vulnerability

HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.

SunlitHCL Software · MyXalyticsEPSS 0.16%via NVD
CVE-2025-52652Low· 3.5
2w ago

HCL MyXalytics was affected by Content Spoofing Vulnerability

HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.

SunlitHCL Software · MyXalyticsEPSS 0.15%via NVD
CVE-2025-52651Low· 3.5
2w ago

HCL MyXalytics was affected by Improper Input validation Vulnerability

HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.

SunlitHCL Software · MyXalyticsEPSS 0.15%via NVD
HCL Software vulnerabilities (CVEs) · VulnSea