CVE-2026-10739: Cato Networks SDP Client
High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.
Affected products
- Cato Networks SDP Client: before 6.12.6 (fixed in 6.12.6)
Published 2026-09-30. Last modified 2026-09-30.