jvn.jp
https://jvn.jp/en/jp/JVN88396700 CVE-2026-40118
MEDIUM
Arcserve UDP Console Incorrectly Specified Destination in Communication Channel
Record summary
CVE-2026-40118 has a selected CVSS score of 5.1 (medium).
Description
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
UDP ConsoleBrowse Arcserve / UDP Console | CVE List | 10.3 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-40118 support.arcserve.com
https://support.arcserve.com/s/article/P00003790?language=en_US&r=94&ui-knowledge-components-aura-actions.KnowledgeArticleVersionCreateDraftFromOnlineAction.createDraftFromOnlineArticle=1