CVE-2026-21765: Hcltech Bigfix Platform

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

Affected products

  • Hcltech Bigfix Platform: from 11.0.0, up to and including 11.0.5

Published 2026-04-02. Last modified 2026-06-17.