CVE-2026-66372
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the see
CVSS
6.8
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 15 sept 2026 · Última mod.: 15 sept 2026 · CWE-337
Sin historial EPSS suficiente todavía.
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.