CVE-2025-2777: SysAid

Critical severity, CVSS 9.8. EPSS: 72.5% chance of exploitation in the next 30 days.

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

Affected products

  • SysAid SysAid: up to and including 23.3.40

Published 2025-05-07. Last modified 2026-06-17.