CVE-2025-40587Disclosure

LOWCVSS 6.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2). The affected application allows arbitrary JavaScript code be included in document titles. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by creating specially crafted document titles that are later viewed by other users of the application.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-10); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-10: 2Mentions · 2026-02-12: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 102-1002-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure2
2026-02-121
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-40587 A vulnerability has been identified in Polarion V2404 (All versions &lt; V2404.5), Polarion V2410 (All versions &lt; V2410.2). The affected application allows arbitrary Jav… https://www.cve.org/CVERecord?id=CVE-2025-40587

    Post summary

    A new CVE (2025-40587) affecting Polarion versions is disclosed, allowing arbitrary Java code execution, but no PoC, exploit, or patch details are provided.

    00010642
    56.5K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA warns of stored XSS flaw in Siemens Polarion ALM (pre-V2506) CISA published ICS Advisory ICSA-26-043-02 (Feb 12, 2026) highlighting a stored XSS vulnerability (CVE-2025-40587) in Siemens Polarion that lets authenticated attackers inject JavaScript via crafted document titles, potentially enabling session theft and user impersonation when others view the content. Update affected Polarion branches (e.g., V2404 and V2410 lines) to the fixed releases to reduce exposure in software/engineering lifecycle environments. 🎯 Target: Global/Software Development (ALM/Engineering) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-02

    Post summary

    CISA alerts of a stored XSS flaw (CVE‑2025‑40587) in Siemens Polarion ALM, advising users to upgrade to patched releases to mitigate potential session theft and impersonation risks.

    0000076
    191 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2025-40587 - Siemens - Polarion V2404 - https://www.redpacketsecurity.com/cve-alert-cve-2025-40587-siemens-polarion-v2404/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-40587 #siemens #polarion-v2404

    Post summary

    A CVE alert for Siemens Polarion V2404 (CVE-2025-40587) was posted with a link to a security advisory, but no PoC, exploit details, or mitigation steps were included in the text.

    0000098
    3.5K followersView on X

Explore more