CVE-2026-66249EPSS p0.9%

CVE-2026-66249CVE-2026-66249

Description

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.

Scoring

CVSS 3.1 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS0.10% probability of exploitation · percentile 0.9% · 2026-10-05T12:00:23Z
Last modified2026-10-01
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.