CVE-2025-52660: Hcltech Aion

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

Affected products

Published 2026-01-19. Last modified 2026-06-17.