cbcvebase.
CVE-2026-22618
published 2026-04-16

CVE-2026-22618: A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute…

PriorityP434high7.1CVSS 3.1
AVNACLPRNUIRSUCLIHAN
EPSS
0.23%
14.1th percentile
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

Affected

2 ranges
VendorProductVersion rangeFixed in
eatonintelligent_power_protector< 2.002.00
eatonipp_software< 2.02.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.