CVE-2026-21765Disclosure(hcltech / bigfix_platform)

LOWCVSS 7.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch hcltech bigfix_platform systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bigfix_platform

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
bigfix_platform

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-02: 5Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 504-02
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21765: HIGH] HCL BigFix Platform vulnerable to insecure permissions on private cryptographic keys on Windows hosts. Ensure proper file system settings for enhanced security.#cve,CVE-2026-21765,#cybersecurity https://cvefind.com/CVE-2026-21765

    Post summary

    The post announces the CVE-2026-21765 vulnerability in HCL BigFix Platform, explaining insecure permissions on cryptographic key files and advising proper file system settings as a mitigation.

    0000037
    617 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-21765 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-21765 #CVE-2026-21765 #CVE #High #CyberSecurity #InfoSec https://t.co/zbGxjO8I31

    Post summary

    The tweet announces CVE-2026-21765 as a high‑severity vulnerability with no evidence of a PoC, exploit, or patch.

    0000036
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21765 HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subj… https://www.cve.org/CVERecord?id=CVE-2026-21765

    Post summary

    CVE‑2026‑21765 impacts HCL BigFix Platform by allowing insecure permissions on private cryptographic keys on Windows hosts; no exploitation, patch, or PoC details are provided.

    00000113
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-21765 - HCL BigFix Platform is affected by insecure permissions on private cryptographic keys Intel Report: https://ift.tt/YUB1SLG

    Post summary

    The alert notes that HCL BigFix is affected by CVE‑2026‑21765 due to insecure key permissions, but offers no PoC, exploit, or patch information.

    0000041
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-21765 - High HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive... https://www.thehackerwire.com/vulnerability/CVE-2026-21765/ https://t.co/Sx79LcYOPC

    Post summary

    The post announces CVE-2026-21765 as a high-severity issue affecting HCL BigFix Platform due to overly permissive permissions on private cryptographic keys on Windows hosts.

    0000053
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphcltechbigfix_platform---

Explore more