{"schema_version":1,"title":"HCL vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in HCL: 1 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-32000, was published on 24 September 2026. 4 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/hcl","json_url":"https://junglewise.ai/threats/vendors/hcl.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/hcl","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":31,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":5,"last_90_days":12,"last_365_days":31},"latest":[{"cve":"CVE-2025-32000","cvss":4.3,"epss":0.0021,"slug":"cve-2025-32000-hcl-sametime-is-vulnerable-to-insufficient-input-sanitization-the","title":"HCL Sametime insufficient input sanitization","severity":"medium","exploited":false,"published_at":"2026-09-24T16:17:06.087+00:00","url":"https://junglewise.ai/threats/cve-2025-32000-hcl-sametime-is-vulnerable-to-insufficient-input-sanitization-the"},{"cve":"CVE-2026-67071","cvss":6.5,"epss":0.0038,"slug":"cve-2026-67071-hcl-devops-deploy-information-disclosure-in-redacted-property","title":"HCL DevOps Deploy information disclosure in redacted property processing","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:18.81+00:00","url":"https://junglewise.ai/threats/cve-2026-67071-hcl-devops-deploy-information-disclosure-in-redacted-property"},{"cve":"CVE-2025-52657","cvss":3.5,"epss":0.0016,"slug":"cve-2025-52657-hcl-myxalytics-input-validation-denial-of-service","title":"HCL MyXalytics input validation denial of service","severity":"low","exploited":false,"published_at":"2026-09-07T11:17:20.47+00:00","url":"https://junglewise.ai/threats/cve-2025-52657-hcl-myxalytics-input-validation-denial-of-service"},{"cve":"CVE-2025-52652","cvss":3.5,"epss":0.0015,"slug":"cve-2025-52652-hcl-myxalytics-content-spoofing","title":"HCL MyXalytics content spoofing","severity":"low","exploited":false,"published_at":"2026-09-07T11:17:20.36+00:00","url":"https://junglewise.ai/threats/cve-2025-52652-hcl-myxalytics-content-spoofing"},{"cve":"CVE-2025-52651","cvss":3.5,"epss":0.0015,"slug":"cve-2025-52651-hcl-myxalytics-input-validation-vulnerability","title":"HCL MyXalytics input validation vulnerability","severity":"low","exploited":false,"published_at":"2026-09-07T11:17:19.503+00:00","url":"https://junglewise.ai/threats/cve-2025-52651-hcl-myxalytics-input-validation-vulnerability"},{"cve":"CVE-2026-21808","cvss":4.1,"epss":0.001,"slug":"cve-2026-21808-hcl-bigfix-quantum-risk-analyzer-verbose-logging-information","title":"HCL BigFix Quantum Risk Analyzer verbose logging information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-26T23:17:12.833+00:00","url":"https://junglewise.ai/threats/cve-2026-21808-hcl-bigfix-quantum-risk-analyzer-verbose-logging-information"},{"cve":"CVE-2026-21807","cvss":3.9,"epss":0.0009,"slug":"cve-2026-21807-hcl-bigfix-quantum-risk-analyzer-stack-buffer-overflow","title":"HCL BigFix Quantum Risk Analyzer stack buffer overflow","severity":"low","exploited":false,"published_at":"2026-08-26T23:17:12.713+00:00","url":"https://junglewise.ai/threats/cve-2026-21807-hcl-bigfix-quantum-risk-analyzer-stack-buffer-overflow"},{"cve":"CVE-2026-21810","cvss":4.4,"epss":0.0007,"slug":"cve-2026-21810-hcl-bigfix-quantum-risk-analyzer-hardcoded-resource-and-binary","title":"HCL BigFix Quantum Risk Analyzer hardcoded resource and binary integrity issues","severity":"medium","exploited":false,"published_at":"2026-08-26T22:16:23.447+00:00","url":"https://junglewise.ai/threats/cve-2026-21810-hcl-bigfix-quantum-risk-analyzer-hardcoded-resource-and-binary"},{"cve":"CVE-2026-21809","cvss":3.9,"epss":0.0009,"slug":"cve-2026-21809-hcl-bigfix-quantum-risk-analyzer-information-disclosure-in","title":"HCL BigFix Quantum Risk Analyzer information disclosure in validation","severity":"low","exploited":false,"published_at":"2026-08-26T22:16:23.323+00:00","url":"https://junglewise.ai/threats/cve-2026-21809-hcl-bigfix-quantum-risk-analyzer-information-disclosure-in"},{"cve":"CVE-2026-56547","cvss":3.5,"epss":0.0028,"slug":"cve-2026-56547-hcl-traveler-apple-profile-improper-input-validation","title":"HCL Traveler Apple profile improper input validation","severity":"low","exploited":false,"published_at":"2026-08-26T20:17:54.19+00:00","url":"https://junglewise.ai/threats/cve-2026-56547-hcl-traveler-apple-profile-improper-input-validation"},{"cve":"CVE-2026-56619","cvss":5.4,"epss":0.0023,"slug":"cve-2026-56619-hcl-bigfix-mobile-reflected-xss-in-user-input-handling","title":"HCL BigFix Mobile reflected XSS in user input handling","severity":"medium","exploited":false,"published_at":"2026-08-10T17:17:35.17+00:00","url":"https://junglewise.ai/threats/cve-2026-56619-hcl-bigfix-mobile-reflected-xss-in-user-input-handling"},{"cve":"CVE-2026-56620","cvss":4.3,"epss":0.003,"slug":"cve-2026-56620-hcl-bigfix-mobile-information-disclosure-via-exception-handling","title":"HCL BigFix Mobile information disclosure via exception handling","severity":"medium","exploited":false,"published_at":"2026-08-10T16:19:48.443+00:00","url":"https://junglewise.ai/threats/cve-2026-56620-hcl-bigfix-mobile-information-disclosure-via-exception-handling"},{"cve":"CVE-2026-21837","cvss":9.8,"slug":"cve-2026-21837-hcl-digital-experience-os-command-injection-in-digital-asset","title":"HCL Digital Experience OS command injection in Digital Asset Management API","severity":"info","exploited":false,"published_at":"2026-06-05T07:16:30.027+00:00","url":"https://junglewise.ai/threats/cve-2026-21837-hcl-digital-experience-os-command-injection-in-digital-asset"},{"cve":"CVE-2026-21826","cvss":6.1,"slug":"cve-2026-21826-hcl-digital-experience-host-header-injection","title":"HCL Digital Experience Host header injection","severity":"medium","exploited":false,"published_at":"2026-06-05T07:16:29.883+00:00","url":"https://junglewise.ai/threats/cve-2026-21826-hcl-digital-experience-host-header-injection"},{"cve":"CVE-2026-21825","cvss":6.1,"slug":"cve-2026-21825-hcl-digital-experience-compose-reflected-xss-in-search-center","title":"HCL Digital Experience Compose reflected XSS in search center","severity":"medium","exploited":false,"published_at":"2026-06-05T07:16:29.707+00:00","url":"https://junglewise.ai/threats/cve-2026-21825-hcl-digital-experience-compose-reflected-xss-in-search-center"},{"cve":"CVE-2025-62338","cvss":3.3,"slug":"cve-2025-62338-hcl-bigfix-cloud-lifecycle-management-information-exposure-via","title":"HCL BigFix Cloud Lifecycle Management information exposure via lack of input validation","severity":"low","exploited":false,"published_at":"2026-06-04T14:16:35.33+00:00","url":"https://junglewise.ai/threats/cve-2025-62338-hcl-bigfix-cloud-lifecycle-management-information-exposure-via"},{"cve":"CVE-2025-59874","cvss":8.1,"slug":"cve-2025-59874-hcl-hive-telco-observability-missing-csp-directives-in-keycloak","title":"HCL Hive Telco Observability Missing CSP Directives in Keycloak","severity":"high","exploited":false,"published_at":"2026-06-04T14:16:35.18+00:00","url":"https://junglewise.ai/threats/cve-2025-59874-hcl-hive-telco-observability-missing-csp-directives-in-keycloak"},{"cve":"CVE-2026-21785","cvss":4,"slug":"cve-2026-21785-hcl-bigfix-remote-control-csp-bypass-in-webui","title":"HCL BigFix Remote Control CSP bypass in WebUI","severity":"medium","exploited":false,"published_at":"2026-05-27T21:16:17.327+00:00","url":"https://junglewise.ai/threats/cve-2026-21785-hcl-bigfix-remote-control-csp-bypass-in-webui"},{"cve":"CVE-2026-21836","cvss":6.5,"slug":"cve-2026-21836-hcl-dominoiq-broken-access-control-in-rag-feature","title":"HCL DominoIQ broken access control in RAG feature","severity":"medium","exploited":false,"published_at":"2026-05-20T14:16:36.373+00:00","url":"https://junglewise.ai/threats/cve-2026-21836-hcl-dominoiq-broken-access-control-in-rag-feature"},{"cve":"CVE-2025-62317","cvss":2.6,"slug":"cve-2025-62317-hcl-aion-sensitive-information-disclosure-in-url-parameters","title":"HCL AION sensitive information disclosure in URL parameters","severity":"low","exploited":false,"published_at":"2026-05-14T17:16:19.107+00:00","url":"https://junglewise.ai/threats/cve-2025-62317-hcl-aion-sensitive-information-disclosure-in-url-parameters"},{"cve":"CVE-2025-62316","cvss":2.3,"slug":"cve-2025-62316-hcl-aion-missing-security-headers","title":"HCL AION missing security headers","severity":"low","exploited":false,"published_at":"2026-05-14T17:16:18.957+00:00","url":"https://junglewise.ai/threats/cve-2025-62316-hcl-aion-missing-security-headers"},{"cve":"CVE-2025-62313","cvss":5.4,"slug":"cve-2025-62313-hcl-aion-improper-restriction-of-authentication-attempts","title":"HCL AION improper restriction of authentication attempts","severity":"medium","exploited":false,"published_at":"2026-05-14T17:16:18.66+00:00","url":"https://junglewise.ai/threats/cve-2025-62313-hcl-aion-improper-restriction-of-authentication-attempts"},{"cve":"CVE-2025-62312","cvss":3,"slug":"cve-2025-62312-hcl-aion-insufficiently-protected-credentials-in-authentication","title":"HCL AION insufficiently protected credentials in authentication mechanism","severity":"low","exploited":false,"published_at":"2026-05-14T17:16:18.48+00:00","url":"https://junglewise.ai/threats/cve-2025-62312-hcl-aion-insufficiently-protected-credentials-in-authentication"},{"cve":"CVE-2025-62311","cvss":4.3,"slug":"cve-2025-62311-hcl-aion-cleartext-transmission-of-sensitive-information","title":"HCL AION cleartext transmission of sensitive information","severity":"medium","exploited":false,"published_at":"2026-05-14T17:16:18.337+00:00","url":"https://junglewise.ai/threats/cve-2025-62311-hcl-aion-cleartext-transmission-of-sensitive-information"},{"cve":"CVE-2025-62310","cvss":5.4,"slug":"cve-2025-62310-hcl-aion-cleartext-transmission-of-sensitive-information","title":"HCL AION cleartext transmission of sensitive information","severity":"medium","exploited":false,"published_at":"2026-05-14T17:16:18.19+00:00","url":"https://junglewise.ai/threats/cve-2025-62310-hcl-aion-cleartext-transmission-of-sensitive-information"}],"vendor":{"hub":true,"name":"HCL","slug":"hcl","homepage":"https://www.hcltechsw.com/","description":"HCL Technologies is a multinational information technology services and consulting company.","url":"https://junglewise.ai/threats/vendors/hcl"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-21821","cvss":8.3,"slug":"cve-2026-21821-hcl-bigfix-scm-reporting-use-of-end-of-life-jquery-1-x-library","title":"HCL BigFix SCM Reporting use of end-of-life jQuery 1.x library","severity":"high","exploited":false,"published_at":"2026-05-13T21:16:41.59+00:00","url":"https://junglewise.ai/threats/cve-2026-21821-hcl-bigfix-scm-reporting-use-of-end-of-life-jquery-1-x-library"},{"cve":"CVE-2025-59874","cvss":8.1,"slug":"cve-2025-59874-hcl-hive-telco-observability-missing-csp-directives-in-keycloak","title":"HCL Hive Telco Observability Missing CSP Directives in Keycloak","severity":"high","exploited":false,"published_at":"2026-06-04T14:16:35.18+00:00","url":"https://junglewise.ai/threats/cve-2025-59874-hcl-hive-telco-observability-missing-csp-directives-in-keycloak"},{"cve":"CVE-2026-67071","cvss":6.5,"epss":0.0038,"slug":"cve-2026-67071-hcl-devops-deploy-information-disclosure-in-redacted-property","title":"HCL DevOps Deploy information disclosure in redacted property processing","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:18.81+00:00","url":"https://junglewise.ai/threats/cve-2026-67071-hcl-devops-deploy-information-disclosure-in-redacted-property"},{"cve":"CVE-2025-15633","cvss":6.5,"epss":0.0023,"slug":"cve-2025-15633-hcl-bigfix-webui-improper-authorization-in-internal-endpoints","title":"HCL BigFix WebUI improper authorization in internal endpoints","severity":"medium","exploited":false,"published_at":"2026-05-09T06:16:07.413+00:00","url":"https://junglewise.ai/threats/cve-2025-15633-hcl-bigfix-webui-improper-authorization-in-internal-endpoints"},{"cve":"CVE-2026-21836","cvss":6.5,"slug":"cve-2026-21836-hcl-dominoiq-broken-access-control-in-rag-feature","title":"HCL DominoIQ broken access control in RAG feature","severity":"medium","exploited":false,"published_at":"2026-05-20T14:16:36.373+00:00","url":"https://junglewise.ai/threats/cve-2026-21836-hcl-dominoiq-broken-access-control-in-rag-feature"},{"cve":"CVE-2026-21826","cvss":6.1,"slug":"cve-2026-21826-hcl-digital-experience-host-header-injection","title":"HCL Digital Experience Host header injection","severity":"medium","exploited":false,"published_at":"2026-06-05T07:16:29.883+00:00","url":"https://junglewise.ai/threats/cve-2026-21826-hcl-digital-experience-host-header-injection"},{"cve":"CVE-2026-21825","cvss":6.1,"slug":"cve-2026-21825-hcl-digital-experience-compose-reflected-xss-in-search-center","title":"HCL Digital Experience Compose reflected XSS in search center","severity":"medium","exploited":false,"published_at":"2026-06-05T07:16:29.707+00:00","url":"https://junglewise.ai/threats/cve-2026-21825-hcl-digital-experience-compose-reflected-xss-in-search-center"},{"cve":"CVE-2026-56619","cvss":5.4,"epss":0.0023,"slug":"cve-2026-56619-hcl-bigfix-mobile-reflected-xss-in-user-input-handling","title":"HCL BigFix Mobile reflected XSS in user input handling","severity":"medium","exploited":false,"published_at":"2026-08-10T17:17:35.17+00:00","url":"https://junglewise.ai/threats/cve-2026-56619-hcl-bigfix-mobile-reflected-xss-in-user-input-handling"},{"cve":"CVE-2025-62313","cvss":5.4,"slug":"cve-2025-62313-hcl-aion-improper-restriction-of-authentication-attempts","title":"HCL AION improper restriction of authentication attempts","severity":"medium","exploited":false,"published_at":"2026-05-14T17:16:18.66+00:00","url":"https://junglewise.ai/threats/cve-2025-62313-hcl-aion-improper-restriction-of-authentication-attempts"},{"cve":"CVE-2025-62310","cvss":5.4,"slug":"cve-2025-62310-hcl-aion-cleartext-transmission-of-sensitive-information","title":"HCL AION cleartext transmission of sensitive information","severity":"medium","exploited":false,"published_at":"2026-05-14T17:16:18.19+00:00","url":"https://junglewise.ai/threats/cve-2025-62310-hcl-aion-cleartext-transmission-of-sensitive-information"}],"generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[{"name":"HCL AION","slug":"aion","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/aion"},{"name":"HCL BigFix Quantum Risk Analyzer","slug":"bigfix-quantum-risk-analyzer","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/bigfix-quantum-risk-analyzer"},{"name":"HCL Digital Experience Compose","slug":"digital-experience-compose","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/digital-experience-compose"},{"name":"HCL MyXalytics","slug":"myxalytics","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/myxalytics"}]}