CVE-2025-31973: Hcltech Bigfix Service Management
Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
Affected products
- Hcltech Bigfix Service Management: version 23.0 only
Published 2026-05-20. Last modified 2026-07-24.