CVE-2026-92680: Araxis Merge

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.

Affected products

  • Araxis Merge: from 2011.4074, before 2026.1 (fixed in 2026.1)

Published 2026-09-24. Last modified 2026-09-26.