CVE-2026-14466
published 2026-09-04CVE-2026-14466: It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions…
PriorityP420medium4.3CVSS 3.1
AVAACLPRHUIRSUCHINAN
EPSS
0.16%
4.6th percentile
It’s possible to run a stored XSS in Stormshield’s web administration panel.
To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| stormshield | stormshield_network_security | 4.8.0 – 4.8.16 | — |
| stormshield | stormshield_network_security | 5.0.0 – 5.0.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-04
Published