CVE-2026-16971: Dfir-Iris Iris-Web
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
Affected products
- Dfir-Iris Iris-Web: version 2.4.26 only
Published 2026-07-30. Last modified 2026-07-30.