CVE-2026-14466: Stormshield Network Security

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.

Affected products

  • Stormshield Stormshield Network Security: from 4.8.0, up to and including 4.8.16; from 5.0.0, up to and including 5.0.6

Published 2026-09-04. Last modified 2026-09-08.