CVE-2026-22322Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create a trunk entry containing malicious HTML/JavaScript code. When the affected page is viewed, the injected script executes in the context of the victim’s browser, enabling unauthorized actions such as interface manipulation. The session cookie is secured by the httpOnly Flag. Therefore an attacker is not able to take over the session of an authenticated user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-18: 4Technical Details · 2026-03-18: 303-18
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-22322 A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create a trunk entry co… https://www.cve.org/CVERecord?id=CVE-2026-22322

    Post summary

    The post announces discovery of CVE‑2026‑22322, a stored XSS flaw in Link Aggregation that permits unauthenticated attackers to create trunk entries; no PoC, exploit, patch, or active exploitation is discussed.

    00000155
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22322 Stored XSS in Link Aggregation Configuration Interface Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22322

    Post summary

    The post announces CVE-2026-22322, a Stored XSS flaw in the Link Aggregation Configuration Interface that can lead to remote code execution, and links to a vulnerability detail page.

    0000058
    4.0K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-22322 - Phoenix Contact - FL SWITCH 2005 - https://www.redpacketsecurity.com/cve-alert-cve-2026-22322-phoenix-contact-fl-switch-2005/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-22322 #phoenix-contact #fl-switch-2005

    Post summary

    A brief CVE alert for CVE-2026-22322 affecting Phoenix Contact FL SWITCH 2005 is posted, but it contains no technical details, exploit evidence, or remediation steps.

    0000073
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22322 - Stored Cross‑Site Scripting in Link Aggregation Name Handling Intel Report: https://ift.tt/kPxTrlv

    Post summary

    Alert announces CVE‑2026‑22322, a stored XSS flaw in Link Aggregation Name handling, with a brief technical note and a link to an intel report; no PoC, exploit code, or evidence of active exploitation is provided.

    0000026
    335 followersView on X

Explore more