← back

CVE-2026-15639

hype MOSTLY HYPE · 28 hack

Same-day publication chatter; no PoC, KEV, or exploitation signal yet; speculation on patch status.

What: Reflected XSS in Delinea Secret Server On-Prem (versions 10.2.19–11.9.48) allowing attackers to execute arbitrary JavaScript via malicious links if users click them.

Why it matters: Published today; no CVSS/EPSS scores yet, not KEV-listed. Affects privileged access management software. Social chatter flags unclear patch status and risk of session theft, but no confirmed PoC or in-the-wild exploitation reported. Early-stage advisory noise.

Where it's seen: Two Bluesky posts citing the CVE hours after publication, referencing threat radar and NVD descriptions. No vendor advisory, PoC, or defender triage activity visible yet.

RISK: MODERATE — Delinea product; XSS can steal sessions but requires user click; patch timeline unknown.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/16/2026, 3:13:08 AM

Description

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

Weaknesses