CVE-2026-18360: Dfir-Iris Iris-Web

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

Affected products

Published 2026-07-30. Last modified 2026-07-30.