← Vulnerability feed

Vulnerability record · CVE-2026-56609 · published 3 August 2026

CVE-2026-56609: Hcltech icontrol broken cryptographic algorithm vulnerability

Hcltech · Icontrol

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.

6.5 CVSS 3.1 Medium EPSS 0.15% · top 96.1% CWE-327 · Broken cryptographic algorithm
6.5CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
5 Aug 2026Last modified by NVD

Description

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-56609 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-52612Hcltech icontrol csv injection vulnerabilityHCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was c…EPSS 0.20%5.3CVE-2026-56608Hcltech icontrol improper access control vulnerabilityHCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…EPSS 0.27%5.3CVE-2026-56568Hcltech icontrol error message information leak vulnerabilityHCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra…EPSS 0.33%5.3CVE-2026-56570Hcltech icontrol insufficiently protected credentials vulnerabilityHCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse…EPSS 0.30%5.3CVE-2026-56571Hcltech icontrol error message information leak vulnerabilityHCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa…EPSS 0.29%5.3CVE-2025-62340Hcltech icontrol insufficient session expiration vulnerabilityHCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to au…EPSS 0.20%5.3CVE-2025-52609Hcltech icontrol vulnerabilityHCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS fi…EPSS 0.16%4.3CVE-2025-52611Hcltech icontrol error message information leak vulnerabilityHCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being a…EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2026-56609), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.