CVE-2025-31976: Hcltech Bigfix Service Management

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .

Affected products

  • Hcltech Bigfix Service Management: version 23.0 only

Published 2026-05-06. Last modified 2026-10-07.