CVE-2026-40118
MEDIUMArcserve Udp Console < 10.3 - Information Disclosure
Title source: ruleDescription
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
Scores
CVSS v3
6.3
EPSS
0.0004
EPSS Percentile
10.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Details
CWE
CWE-941
Status
published
Products (1)
Arcserve/UDP Console
10.3
Published
Apr 16, 2026
Tracked Since
Apr 16, 2026