PatchSiren

Keyfactor CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Keyfactor CVE published 2026-09-15

CVE-2026-25827

CVE-2026-25827 is a low-severity vulnerability in Keyfactor SignServer before version 7.6.0. An admin user can potentially reveal information about file existence on the server through specific property settings. The affected properties are ATTRIBUTESFILE, KEYSTOREPATH, and TRUSTSTOREPATH. Defenders responsible for Keyfactor SignServer deployments, especially those with admin user access, should assess ex [truncated]

MEDIUM Keyfactor CVE published 2026-09-15

CVE-2026-25826

CVE-2026-25826 is a vulnerability in Keyfactor SignServer before version 7.6.0. An admin user can set the ATTRIBUTESFILE attribute in PKCS11CryptoToken to a readable file, causing an error that prints the file content to the application server log. A user with SignServer admin access and access to server logs can read file content accessible by the local user JBoss.

LOW Keyfactor CVE published 2026-09-15

CVE-2026-25825

CVE-2026-25825 is a low-severity vulnerability in Keyfactor SignServer before version 7.6.0. An admin user can exploit this issue to write files to arbitrary directories in the server filesystem, potentially overwriting files accessible by the local user JBoss. This vulnerability allows for unauthorized file writes, which could lead to further exploitation. Defenders should assess exposure and prioritize [truncated]