CVE-2025-2776: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-07-22. EPSS: 64.7% chance of exploitation in the next 30 days.
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
Affected products
- SysAid SysAid: up to and including 23.3.40
Published 2025-05-07. Last modified 2026-06-17.