CVE-2026-62645
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be us
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-306
Not enough EPSS history yet.
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-19397——
——0Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.
Refer to the '
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.11hCVE-2026-865439.8 CRI—
——0knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.15hCVE-2026-865065.9 MED—
——0In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data3hCVE-2026-865028.4 HIG—
——0In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts3hCVE-2026-864863.7 LOW—
——0In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank3hCVE-2026-864809.8 CRI—
——0In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges3h