Multiple vulnerabilities in Stormshield Management Center (June 29, 2026)
Multiple vulnerabilities have been discovered in Stormshield Management Center. They allow an attacker to cause remote arbitrary code execution, data confidentiality breaches, and data integrity breaches.
CSIRTS triage
- What
- Multiple vulnerabilities can lead to remote code execution and breaches of data confidentiality and integrity.
- Who is affected
- Users of Stormshield Management Center, specifics not detailed in the advisory.
- Urgency
- Remediation is urgent due to the potential for remote code execution and data breaches.
- Action
- Update Stormshield Management Center to the latest version to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Stormshield Management Center
Get an email when a new Stormshield Management Center advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0816/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-66370.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-64731.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-66380.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64750.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-64770.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-6637 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6473 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6638 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6475 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6477 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0321 [1.00] [M/H] Multiple vulnerabilities fixed in IBM AIX and IBM PowerVM VIOSncsc-nl
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Splunk products (20 August 2026)cert-fr-avis
- unknownPostgreSQL Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Tenable products (August 4, 2026)cert-fr-avis
- unknownF5 Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Tenable Security Center (July 21, 2026)cert-fr-avis
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21