Vendor
HCL Software vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 52 vulnerabilities in HCL Software: 0 in the last 7 days and 45 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-56583, was published on 21 July 2026. 8 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 45
- Critical, all time
- 1
- Exploited in the wild
- 0
About HCL Software
A division of HCL Technologies that develops and markets enterprise software solutions.
HCL Software technologies
Latest HCL Software vulnerabilities
- CVE-2026-56583: HCL MyCloud concurrent login vulnerabilitylowCVSS 3.1
- CVE-2026-56582: HCL MyCloud SSL/TLS LUCKY13 padding oracle vulnerabilitylowCVSS 3.1
- CVE-2026-56581: HCL MyCloud missing cookie path attributelowCVSS 2.6
- CVE-2026-56580: HCL MyCloud use of unmaintained components in IIS ServerlowCVSS 2.2
- CVE-2026-56579: HCL MyCloud sensitive information disclosure in HTTP responselowCVSS 3.1
- CVE-2026-56578: HCL MyCloud server version disclosurelowCVSS 2.2
- CVE-2026-56577: HCL MyCloud weak password policylowCVSS 3.1
- CVE-2026-56586: HCL IntelliOps Event Management missing X-Content-Type-Options headerlowCVSS 3.1
- CVE-2026-56585: HCL IntelliOps Event Management missing X-Frame-Options headerlowCVSS 3.1
- CVE-2026-56587: HCL IntelliOps Event Management missing HSTS enforcementlowCVSS 3.7
- CVE-2026-56584: HCL IntelliOps Event Management Information Disclosure in Nginx serverlowCVSS 3.7
- CVE-2025-59866: HCL DFMPro and DFX installers privilege escalation via insecure file permissionslowCVSS 3.3
- CVE-2024-42214: HCL Aftermarket EPC information disclosure via HTTP OPTIONS methodmediumCVSS 5.3
- CVE-2024-23578: HCL Aftermarket EPC permissive CORS policymediumCVSS 4.2
- CVE-2024-23577: HCL Aftermarket EPC Host header poisoningmediumCVSS 4.3
- CVE-2024-23575: HCL Aftermarket EPC information disclosure via detailed error messagesmediumCVSS 5.3
- CVE-2024-23574: HCL Aftermarket EPC user enumeration via response discrepancymediumCVSS 5.3
- CVE-2024-23573: HCL Aftermarket EPC Lucky 13 timing attack in TLS/DTLSlowCVSS 3.7
- CVE-2024-23572: HCL Aftermarket EPC insecure session cookie attributesmediumCVSS 4.2
- CVE-2024-23571: HCL Aftermarket EPC improper caching policy in web interfacemediumCVSS 4.3
- CVE-2024-23570: HCL Aftermarket EPC clickjacking vulnerabilitymediumCVSS 4.3
- CVE-2024-23569: HCL Aftermarket EPC missing X-XSS-Protection headermediumCVSS 4.3
- CVE-2024-23568: HCL Aftermarket EPC information disclosure via server version leakagemediumCVSS 5.3
- CVE-2024-23567: HCL Aftermarket EPC sensitive information exposure in URL parametersmediumCVSS 4.3
- CVE-2024-23566: HCL Aftermarket EPC brute force vulnerability due to missing CAPTCHAmediumCVSS 6.5
Most severe HCL Software vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-23564: HCL Aftermarket EPC business logic vulnerability in password recoverycriticalCVSS 9.1
- CVE-2026-35149: HCL DFXServer authentication bypass via response manipulationhighCVSS 8.2
- CVE-2026-35147: HCL DFXServer broken authentication via direct API accesshighCVSS 8.2
- CVE-2023-37524: HCL Traveler for Microsoft Outlook use of unmaintained .NET Framework 4.5highCVSS 7.7
- CVE-2024-23581: HCL Traveler for Microsoft Outlook use of unmaintained componentsmediumCVSS 6.7
- CVE-2024-23566: HCL Aftermarket EPC brute force vulnerability due to missing CAPTCHAmediumCVSS 6.5
- CVE-2026-21770: HCL Traveler for Microsoft Outlook DLL hijackingmediumCVSS 6.5
- CVE-2026-56460: HCL DevOps Deploy and Launch sensitive information disclosure in APImediumCVSS 6.5
- CVE-2026-35148: HCL DFXServer missing access control in API endpointsmediumCVSS 6.3
- CVE-2026-35146: HCL DFXServer unencrypted communication via HTTPmediumCVSS 6.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 30 | 1 | |
| 20 Jul 2026 | 11 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/hcl-software.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "HCL Software vulnerabilities", https://junglewise.ai/threats/vendors/hcl-software, 26 September 2026.