HCLTechsw's vulnerability footprint spans a moderately sized portfolio of enterprise software products including deployment and DevOps automation tools, commerce platforms, and server management utilities, serving integration-heavy IT infrastructure environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure does not show a strong tendency toward public exploitation or confirmed in-the-wild cataloging. The recurring weakness classes center on web application and credential-handling issues—cross-site scripting, insufficient session management, inadequately protected credentials, and insecure sensitive-data storage—reflecting the authentication and user-input demands of web-facing administrative tools and commerce applications. Defenders should prioritize patches affecting internet-reachable deployment and management consoles; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hcltechsw over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56460MEDIUM HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | Jul 9, 2026 | 6.5 | 31 | NO | NO |
CVE-2022-38656CRITICAL HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
| Dec 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-56458HIGH HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is n | Jul 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2020-14245CRITICAL HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. | Feb 4, 2021 | 9.8 | 28 | NO | NO |
CVE-2021-27741CRITICAL " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection" | Aug 13, 2021 | 9.1 | 27 | NO | NO |
CVE-2023-37523CRITICAL Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
| Jan 16, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-14231HIGH A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow | Dec 22, 2020 | 8.8 | 26 | NO | NO |
CVE-2026-56459MEDIUM HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a lo | Jul 9, 2026 | 5.5 | 25 | NO | NO |
CVE-2026-56457MEDIUM HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to | Jun 29, 2026 | 4.3 | 25 | NO | NO |
CVE-2023-37522CRITICAL HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
| Jan 16, 2024 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hcltechsw.
Media articles that mention a CVE ID that affects a product developed by Hcltechsw — matched by CVE ID, not by vendor name.