CVE-2026-10726: Cato Networks SDP Client
Medium severity, CVSS 6.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
Affected products
- Cato Networks SDP Client: before 6.12.6 (fixed in 6.12.6)
Published 2026-09-30. Last modified 2026-09-30.