CVE-2026-66372
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the see
CVSS
6.8
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 15, 2026 · Last modified: Sep 15, 2026 · CWE-337
Not enough EPSS history yet.
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.