HCLtech's vulnerability footprint spans a moderately broad portfolio of enterprise software products including system management, business intelligence, and collaboration platforms such as BigFix Platform, DryIce MyXalytics, AION, Domino, and Connections, positioning the vendor prominently in business-critical and development environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the complexity and integration demands of large enterprise middleware and application-server codebases. The exposure recurs through web-application and information-disclosure weakness classes, including cross-site scripting, cross-site request forgery, improper input neutralization, and sensitive information exposure, which are characteristic of widely deployed server platforms where authentication and request validation are central. Defenders should prioritize HCLtech advisories for products connected to identity, configuration management, or inter-system integration, as these are high-value targets for lateral movement. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hcltech over time
Signals from CVEs in this vendor scope (427 CVEs).
427 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56453CRITICAL HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses b | Jul 16, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-31973CRITICAL HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabili | May 20, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-35149HIGH HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by interc | Jul 16, 2026 | 8.2 | 36 | NO | NO |
CVE-2025-59872CRITICAL HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the se | Jun 17, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-21837HIGH HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typic | Jun 5, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-35147HIGH HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific A | Jul 16, 2026 | 8.2 | 35 | NO | NO |
CVE-2024-23581HIGH The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. | Jun 26, 2026 | 7.8 | 35 | NO | NO |
CVE-2025-55251CRITICAL HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-35142HIGH HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which c | Jul 16, 2026 | 8.2 | 33 | NO | NO |
CVE-2023-37524HIGH HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no | Jun 27, 2026 | 7.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (427 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hcltech.
Media articles that mention a CVE ID that affects a product developed by Hcltech — matched by CVE ID, not by vendor name.