CVE-2025-26318: Tsplus Remote Access

Medium severity, CVSS 5.8. EPSS: 1% chance of exploitation in the next 30 days.

hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

Affected products

  • Tsplus Tsplus Remote Access: before 17.30 (fixed in 17.30)

Published 2025-03-04. Last modified 2026-06-17.