CVE-2026-63359: Equifax Victim Information Notification Exchange

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.

Affected products

  • Equifax Victim Information Notification Exchange: before 2026-05-07 (fixed in 2026-05-07)

Published 2026-07-23. Last modified 2026-08-26.