CVE-2026-66249: Hcl Software Icontrol

Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.

Affected products

Published 2026-10-01. Last modified 2026-10-01.