CVE-2025-2776: SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-07-22. EPSS: 64.7% chance of exploitation in the next 30 days.

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Affected products

  • SysAid SysAid: up to and including 23.3.40

Published 2025-05-07. Last modified 2026-06-17.