CVE-2026-3610General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown functionality of the file /mailinspector/mliUserValidation.php of the component URL Handler. The manipulation of the argument error_description results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 5.4.0 can resolve this issue. You should upgrade the affected component. The vendor was contacted early and responded very professional: "We have already implemented the fix and made a hotfix available to affected customers, ensuring mitigation while the official release 5.4.0 has not yet been published. This allows customers to address the issue immediately, outside the regular release cycle."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-06: 3Technical Details · 2026-03-06: 203-06
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3610 A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown functionality of the file /mailinspector/mliUserValid… https://www.cve.org/CVERecord?id=CVE-2026-3610

    Post summary

    The post announces CVE‑2026‑3610—a vulnerability in HSC Cybersecurity Mailinspector up to version 5.3.2‑3 affecting an unknown functionality in the /mailinspector/mliUserValid file, with no PoC or exploit disclosed.

    00000132
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3610 Cross-Site Scripting in HSC Cybersecurity Mailinspector via URL Handler Argument https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3610

    Post summary

    A brief statement reports CVE‑2026‑3610 as an XSS flaw in Mailinspector, providing limited technical detail but no evidence of exploitation, PoC, or patching.

    0000056
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3610 Intel Report: https://ift.tt/KOM03W8

    Post summary

    A brief threat alert identifies CVE‑2026‑3610 and links to an intel report, but provides no further details or actionable information.

    0000044
    343 followersView on X

Explore more