CVE-2026-10754: Pegasystems Pega Infinity

High severity, CVSS 8.6. EPSS: 0.8% chance of exploitation in the next 30 days.

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

Affected products

Published 2026-08-10. Last modified 2026-09-08.