CVE-2026-92680: Araxis Merge
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
Affected products
- Araxis Merge: from 2011.4074, before 2026.1 (fixed in 2026.1)
Published 2026-09-24. Last modified 2026-09-26.