CVE-2026-53475
critical · 9.3A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
9.3
CVSS
0.3%
EPSS (exploit prob.)
17th
EPSS percentile
2026-06-10
Published
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-295
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| kubev2v | assisted_migration_agent | < 2026-06-10 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-53475