CVE-2026-15639
Same-day publication chatter; no PoC, KEV, or exploitation signal yet; speculation on patch status.
What: Reflected XSS in Delinea Secret Server On-Prem (versions 10.2.19–11.9.48) allowing attackers to execute arbitrary JavaScript via malicious links if users click them.
Why it matters: Published today; no CVSS/EPSS scores yet, not KEV-listed. Affects privileged access management software. Social chatter flags unclear patch status and risk of session theft, but no confirmed PoC or in-the-wild exploitation reported. Early-stage advisory noise.
Where it's seen: Two Bluesky posts citing the CVE hours after publication, referencing threat radar and NVD descriptions. No vendor advisory, PoC, or defender triage activity visible yet.
RISK: MODERATE — Delinea product; XSS can steal sessions but requires user click; patch timeline unknown.
Description
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.