CVE-2026-13462: Payrange

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.

Affected products

Published 2026-07-09. Last modified 2026-07-09.