CVE-2026-65309
CVE-2026-65309 is a high-severity vulnerability with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-257.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 0% (5th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-257
- Published:
- Last modified:
Description
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
Frequently asked questions
- What is CVE-2026-65309?
- ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
- How severe is CVE-2026-65309?
- CVE-2026-65309 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-65309 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (5th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-65309?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-65309 published?
- CVE-2026-65309 was published on 2026-07-31.
References
Other CWE-257 vulnerabilities
- CVE-2025-8095 — Critical (CVSS 9.1): The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as…
- CVE-2025-8904 — High (CVSS 8.5): Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/…
- CVE-2025-34180 — High (CVSS 8.4): NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client,…
- CVE-2025-6996 — High (CVSS 8.4): Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update…
- CVE-2025-6995 — High (CVSS 8.4): Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update…
- CVE-2016-15058 — High (CVSS 8.1): Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior…