cbcvebase.
CVE-2026-8480
published 2026-07-01

CVE-2026-8480: A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked…

PriorityP421medium4.3CVSS 3.1
AVAACLPRNUINSUCLINAN
EPSS
0.09%
0.4th percentile
A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.

Affected

3 ranges
VendorProductVersion rangeFixed in
stormshieldstormshield_network_security4.3.0 – 4.3.41—
stormshieldstormshield_network_security4.4.0 – 4.8.15—
stormshieldstormshield_network_security5.0.2 EA – 5.0.5—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.