CVE-2025-59870: Hcltech Myxalytics

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

Affected products

  • Hcltech Myxalytics: version 6.2 only; version 6.3 only; version 6.4 only; version 6.5 only; version 6.6 only; version 6.7 only

Published 2026-01-16. Last modified 2026-06-17.