CVE-2026-40118: Arcserve UDP Console

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.

Affected products

Published 2026-04-16. Last modified 2026-06-17.