CVE-2026-94214: St Engineering Idirect Evolution
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected products
- St Engineering Idirect Evolution: version 20260717 only
- St Engineering Idirect Velocity Webserver Evolution: version 20260717 only
Published 2026-09-21. Last modified 2026-09-30.