CVE-2026-21753CWE-1104

CVE-2026-21753

Medium · published August 25, 2026

CVSS v3.1
4.2
EPSS
0%
Percentile
3.6
In the wild
Unconfirmed
What it is

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.

The record
Technical detail
CVSS v3.1
4.2 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00139 · 3.6th percentile
Weakness
CWE-1104 · Use of Unmaintained Third Party Components
Published
2026-08-25T15:16Z
References (1)
EPSS history
Timeline
  • 27 AUG 06:21Z
    EPSS moved — → 0%
    epss
  • 25 AUG 10:50Z
    HCL Hive is affected by multiple security vulnerabilities.
    cvelistv5