PatchSiren

LuxSoft CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM LuxSoft CVE published 2026-09-13

CVE-2026-36989

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. This CVE was published on 2026-09-13T21:17:01.140Z and was last modified on 2026-09-22T20:00:03.713Z. The NVD entry is currently Deferred. Defenders responsible for LuxSoft LuxCal deployments should assess exposure and prioritize verification of the vulnerability in their environments. The vulner [truncated]