By vendor
Microfocus vulnerabilities
Known CVEs affecting Microfocus products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-11877HIGH 7.5
CVE-2026-11877 is a high-severity vulnerability in OpenText Access Manager that allows an unauthenticated attacker to modify system configuration via API calls. An attacker on the network can send specially crafted API requests to alter Access Manager settings without providing credentials, potentially compromising authentication, authorization, or system behavior. This vulnerability affects Access Manager versions before 5.1.3.
- CVE-2026-11878MEDIUM 6.1
OpenText Access Manager versions 5.1 through 5.1.2 contain a cross-site scripting (XSS) vulnerability in web page generation. An attacker can inject malicious JavaScript code that executes in the browsers of users accessing the affected system. The vulnerability requires user interaction (such as clicking a crafted link) but does not require authentication, making it accessible to unauthenticated threat actors. While not currently listed in CISA's Known Exploited Vulnerabilities catalog, the combination of network accessibility and user-triggered execution means organizations should prioritize remediation.