CVE-2026-40118: Arcserve UDP Console
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
Affected products
- Arcserve UDP Console: version 10.3 only
Published 2026-04-16. Last modified 2026-06-17.