PULSE
FEED
ransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransomeclipse reclama a DIPECARR · BR · Otherransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransomeclipse reclama a DIPECARR · BR · Other
← All CVEs
CVE WatchOct 2, 2026

CVE-2026-103097

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensit

CVSS

7.5

High

EPSS

0.2%

p4

KEV

—

Exploit Today

1

0-100

Published: Oct 2, 2026 · Last modified: Oct 2, 2026 · CWE-312 · CWE-540 · CWE-798

EPSS · 30d
0.2%EPSS · 30 days0.2%
2026-10-022026-10-08
Technical description

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-848915.9 MED
—
——0IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials.9h
CVE-2026-102368—
—
——0Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.  Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.9h
CVE-2026-842508.4 HIG
—
——0IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.10h
CVE-2026-85488—
0.5%
——0Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place.11h
CVE-2026-85422—
1.0%
——0A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.11h
CVE-2026-928614.0 MED
1.2%
——0The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.10h