CVE-2026-67101
critical · 9.3HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.
9.3
CVSS
0.3%
EPSS (exploit prob.)
19th
EPSS percentile
2026-09-18
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Weaknesses
CWE-918
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-67101