PatchSiren

Microfocus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microfocus CVE published 2026-06-24

CVE-2026-11878

CVE-2026-11878 is a high-severity vulnerability in OpenText Access Manager, a product from Microfocus. The vulnerability is an improper neutralization of input during web page generation, also known as cross-site scripting (XSS). It affects Access Manager versions from 5.1 through 5.1.2. The CVSS score for this vulnerability is 8.2, indicating a high severity. The CVE was published on June 24, 2026, and l [truncated]

HIGH Microfocus CVE published 2026-03-31

CVE-2026-2123

A security audit identified a high-severity privilege escalation vulnerability in Microfocus Operations Agent on Windows. The vulnerability, CVE-2026-2123, allows an attacker to run executables from specific writable locations under certain conditions. This vulnerability was reported by Manuel Rickli and Philippe Leiser of Oneconsult AG. The CVE record was published on 2026-03-31T18:16:46.293Z and last mo [truncated]