SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-35146

HCL DFXServer is affected by an Unencrypted Communication vulnerability.

MEDIUM 6.3EPSS 0.19%

Does this matter?

Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.

Description

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS
0.19% probability · 9th percentile
CISA KEV
Not listed
Weakness
CWE-326
Affected
hcltech/dfx server
Source
psirt@hcl.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.