{"schema_version":1,"title":"HCL Software DFXServer vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in HCL Software DFXServer: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-59866, was published on 17 July 2026.","url":"https://junglewise.ai/threats/technologies/dfxserver","json_url":"https://junglewise.ai/threats/technologies/dfxserver.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/dfxserver","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":5,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":5},"latest":[{"cve":"CVE-2025-59866","cvss":3.3,"slug":"cve-2025-59866-hcl-dfmpro-and-dfx-installers-privilege-escalation-via-insecure","title":"HCL DFMPro and DFX installers privilege escalation via insecure file permissions","severity":"low","exploited":false,"published_at":"2026-07-17T18:17:12.643+00:00","url":"https://junglewise.ai/threats/cve-2025-59866-hcl-dfmpro-and-dfx-installers-privilege-escalation-via-insecure"},{"cve":"CVE-2026-35149","cvss":8.2,"slug":"cve-2026-35149-hcl-dfxserver-authentication-bypass-via-response-manipulation","title":"HCL DFXServer authentication bypass via response manipulation","severity":"high","exploited":false,"published_at":"2026-07-16T12:17:35.87+00:00","url":"https://junglewise.ai/threats/cve-2026-35149-hcl-dfxserver-authentication-bypass-via-response-manipulation"},{"cve":"CVE-2026-35148","cvss":6.3,"slug":"cve-2026-35148-hcl-dfxserver-missing-access-control-in-api-endpoints","title":"HCL DFXServer missing access control in API endpoints","severity":"medium","exploited":false,"published_at":"2026-07-16T12:17:35.733+00:00","url":"https://junglewise.ai/threats/cve-2026-35148-hcl-dfxserver-missing-access-control-in-api-endpoints"},{"cve":"CVE-2026-35147","cvss":8.2,"slug":"cve-2026-35147-hcl-dfxserver-broken-authentication-via-direct-api-access","title":"HCL DFXServer broken authentication via direct API access","severity":"high","exploited":false,"published_at":"2026-07-16T12:17:35.617+00:00","url":"https://junglewise.ai/threats/cve-2026-35147-hcl-dfxserver-broken-authentication-via-direct-api-access"},{"cve":"CVE-2026-35146","cvss":6.3,"slug":"cve-2026-35146-hcl-dfxserver-unencrypted-communication-via-http","title":"HCL DFXServer unencrypted communication via HTTP","severity":"medium","exploited":false,"published_at":"2026-07-16T12:17:35.493+00:00","url":"https://junglewise.ai/threats/cve-2026-35146-hcl-dfxserver-unencrypted-communication-via-http"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"HCL Software Aftermarket EPC","slug":"aftermarket-epc","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/aftermarket-epc"},{"name":"HCL Software DFXAnalytics","slug":"dfxanalytics","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/dfxanalytics"},{"name":"HCL Software MyCloud","slug":"mycloud","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/mycloud"},{"name":"HCL Software DevOps Deploy","slug":"devops-deploy","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/devops-deploy"},{"name":"HCL Software DevOps Launch","slug":"devops-launch","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/devops-launch"},{"name":"HCL Software IntelliOps Event Management","slug":"intelliops-event-management","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/intelliops-event-management"},{"name":"HCL Software Traveler for Microsoft Outlook","slug":"traveler-for-microsoft-outlook","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/traveler-for-microsoft-outlook"}],"technology":{"hub":true,"name":"HCL Software DFXServer","slug":"dfxserver","vendor":{"name":"HCL Software","slug":"hcl-software","url":"https://junglewise.ai/threats/vendors/hcl-software"},"aliases":[],"category":"software","homepage":"https://www.hcl-software.com/","description":"A server component used for data exchange and synchronization within HCL software environments.","url":"https://junglewise.ai/threats/technologies/dfxserver"},"most_severe":[{"cve":"CVE-2026-35149","cvss":8.2,"slug":"cve-2026-35149-hcl-dfxserver-authentication-bypass-via-response-manipulation","title":"HCL DFXServer authentication bypass via response manipulation","severity":"high","exploited":false,"published_at":"2026-07-16T12:17:35.87+00:00","url":"https://junglewise.ai/threats/cve-2026-35149-hcl-dfxserver-authentication-bypass-via-response-manipulation"},{"cve":"CVE-2026-35147","cvss":8.2,"slug":"cve-2026-35147-hcl-dfxserver-broken-authentication-via-direct-api-access","title":"HCL DFXServer broken authentication via direct API access","severity":"high","exploited":false,"published_at":"2026-07-16T12:17:35.617+00:00","url":"https://junglewise.ai/threats/cve-2026-35147-hcl-dfxserver-broken-authentication-via-direct-api-access"},{"cve":"CVE-2026-35148","cvss":6.3,"slug":"cve-2026-35148-hcl-dfxserver-missing-access-control-in-api-endpoints","title":"HCL DFXServer missing access control in API endpoints","severity":"medium","exploited":false,"published_at":"2026-07-16T12:17:35.733+00:00","url":"https://junglewise.ai/threats/cve-2026-35148-hcl-dfxserver-missing-access-control-in-api-endpoints"},{"cve":"CVE-2026-35146","cvss":6.3,"slug":"cve-2026-35146-hcl-dfxserver-unencrypted-communication-via-http","title":"HCL DFXServer unencrypted communication via HTTP","severity":"medium","exploited":false,"published_at":"2026-07-16T12:17:35.493+00:00","url":"https://junglewise.ai/threats/cve-2026-35146-hcl-dfxserver-unencrypted-communication-via-http"},{"cve":"CVE-2025-59866","cvss":3.3,"slug":"cve-2025-59866-hcl-dfmpro-and-dfx-installers-privilege-escalation-via-insecure","title":"HCL DFMPro and DFX installers privilege escalation via insecure file permissions","severity":"low","exploited":false,"published_at":"2026-07-17T18:17:12.643+00:00","url":"https://junglewise.ai/threats/cve-2025-59866-hcl-dfmpro-and-dfx-installers-privilege-escalation-via-insecure"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}