CVE-2025-59108: Dormakaba Access Manager 92xx-k5
Critical severity, CVSS 9.2. EPSS: 0.4% chance of exploitation in the next 30 days.
By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.
Affected products
Published 2026-01-26. Last modified 2026-06-17.