PatchSiren

Pegasystems CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Pegasystems CVE published 2026-08-28

CVE-2026-13761

CVE-2026-13761 is a high-severity vulnerability affecting Pega Platform versions 7.1.0 through 25.1.2. The vulnerability is caused by improper validation of inputs used for loop conditions, potentially leading to a denial of service or other consequences due to excessive looping. Defenders should assess exposure, prioritize remediation, and verify the vulnerability's impact on their systems.

HIGH Pegasystems CVE published 2026-08-10

CVE-2026-10754

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. This vulnerability has a high CVSS score of 8.6 and requires verification of affected versions and secure cryptographic signature validation to prevent potential security control bypass. Defenders responsible for Pega Platform deployments sh [truncated]

MEDIUM Pegasystems CVE published 2026-08-04

CVE-2026-14337

A high-privileged user with a developer role can exploit a Stored Cross-site scripting (XSS) vulnerability in Pega Platform versions 23.1.0 through 25.1.3. This vulnerability affects the user interface component. The vulnerability requires verification of exposure and prioritization of remediation. Defenders responsible for Pega Platform deployments should assess their exposure and prioritize verification [truncated]

HIGH Pegasystems CVE published 2026-06-23

CVE-2025-62180

CVE-2025-62180 is an authorization weakness in Pega Platform versions 8.3.0 through Infinity 25.1.2. This vulnerability may allow authenticated users to access certain additional data via crafted URLs. The CVSS score for this vulnerability is 7.1, indicating a high severity. The CVE was published on June 23, 2026, and last modified on June 23, 2026. The vendor, Pega, has provided security advisories for t [truncated]