CVE-2026-21785: Hclsoftware Bigfix Remote Control Server
Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
Affected products
- Hclsoftware Bigfix Remote Control Server
Published 2026-05-27. Last modified 2026-06-17.