VYPR

SEVD-2026-160-02

by Schneider Electric

CVEs (3)

  • CVE-2026-9717HigJun 25, 2026
    risk 0.47cvss 7.2epss 0.01

    CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged…

  • CVE-2026-9718MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service.

  • CVE-2026-9651MedJun 25, 2026
    risk 0.29cvss 4.4epss 0.00

    CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.