CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] HCL BigFix Mobile: Multiple vulnerabilities

highCVE-2026-56618CVE-2026-56619CVE-2026-56620
An attacker can exploit multiple vulnerabilities in HCL BigFix Mobile to bypass security measures, to perform a Cross-Site Scripting attack, and to disclose information.

CSIRTS triage

What
Multiple vulnerabilities allow security bypass, cross-site scripting, and information disclosure.
Who is affected
HCL BigFix Mobile deployments.
Urgency
High severity; authentication bypass and xss impact warrant prompt patching.
Action
Apply available security patches for HCL BigFix Mobile.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch HCL BigFix Mobile

Get an email when a new HCL BigFix Mobile advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2741

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-56618coverage & exploitation statusNVD · CVE.org
CVE-2026-56619coverage & exploitation statusNVD · CVE.org
CVE-2026-56620coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for HCL BigFix Mobile

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories