Critical Alert 1 Active Exploit Detected Today

CVE-2026-48558 SimpleHelp Authentication Bypass Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower


← Back to CVE List

CVE-2026-12490NVD

Vulnerability Summary

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
Severity Level
UNKNOWN
Published Date
Jun 25, 2026
Last Modified
Jun 25, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.14%Probability
Root Weakness (CWE)
N/A