PatchSiren

Araxis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Araxis CVE published 2026-09-24

CVE-2026-92680

CVE-2026-92680 debrief based on the supplied source corpus. The CVE record was published on 2026-09-24T16:17:14.357Z and has not been modified since then. This vulnerability affects Araxis Merge for Windows, specifically versions 2011.4074 through 2026.0, and involves the insecure storage of user-configured credentials for remote servers in the Windows registry. An authenticated, non-administrative attack [truncated]