HCL vulnerabilities
11 CVEs tracked
HCL appears in recent reports with multiple information disclosure and access control issues across its product portfolio. Key themes include sensitive data exposure in HCL Connections (CVE-2026-56538, CVE-2026-56537), weak TLS versions and missing access controls in HCL iControl (CVE-2026-56609, CVE-2026-56608), as well as shared storage permission problems (CVE-2025-52640) and prompt injection (CVE-2026-21832) in HCL AION. Defenders should prioritize emergency patch management for HCL products, applying the latest security updates for Connections, iControl, AION, and Digital Experience, while also auditing their TLS configurations.
Azərbaycanca: HCL son hesabatlarda bir neçə məhsulu üzrə informasiya sızması və giriş nəzarəti problemləri ilə diqqət çəkir. Əsas mövzular bunlardır: HCL Connections-da məlumat sızması (CVE-2026-56538, CVE-2026-56537), HCL iControl-da zəif TLS versiyalarının dəstəklənməsi və giriş nəzarətinin olmaması (CVE-2026-56609, CVE-2026-56608), eləcə də HCL AION-da paylaşılan yaddaşla bağlı icazə problemləri (CVE-2025-52640) və prompt injection zəifliyi (CVE-2026-21832). Müdafiəçilər HCL məhsulları üçün təcili patch idarəetməsinə, xüsusilə HCL Connections, iControl, AION və Digital Experience üçün buraxılmış təhlükəsizlik yeniləmələrinin tətbiqinə diqqət yetirməli, həmçinin TLS konfiqurasiyasını yoxlamalıdırlar.
This vendor's CVEs11
This hub is built from skopnix's own reporting on HCL: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.