Assessment
Why it matters
The technology is frequently internet-facing, but current evidence does not show exploitation and authentication is required.
Who should care
- Remote access platform owners
- Vulnerability management teams
- Security monitoring teams
Response plan
What I would do
- Identify affected appliances.
- Check administrative exposure.
- Plan the supported update.
- Monitor vendor and exploitation reporting.
- Escalate if new evidence appears.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-284: Improper Access Control
- Affected versions
- Demonstration range: selected Connect Secure releases
- Published
- 16 Aug 2026
- Attack vector
- Network
- Privileges required
- Low
- User interaction
- None
Signal timeline
- Advisory published
- Initial EPSS available
- No exploitation confirmed
- Signal remains 58