CVE-2026-10726EPSS p0.0%

CVE-2026-10726CVE-2026-10726

Description

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

Scoring

EPSS0.06% probability of exploitation · percentile 0.0% · 2026-10-02T12:00:20Z
Last modified2026-09-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.