CVE-2026-6805: Thalesgroup Ercom Cryptobox

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force attack of the access code associated to this sharing link.

Affected products

  • Thalesgroup Ercom Cryptobox: from 4.37.248, before 4.38.0 (fixed in 4.38.0)

Published 2026-05-07. Last modified 2026-06-17.