CVE-2026-13761 is a high-severity vulnerability affecting Pega Platform versions 7.1.0 through 25.1.2. The vulnerability is caused by improper validation of inputs used for loop conditions, potentially leading to a denial of service or other consequences due to excessive looping. Defenders should assess exposure, prioritize remediation, and verify the vulnerability's impact on their systems.
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls. This vulnerability has a high CVSS score of 8.6 and requires verification of affected versions and secure cryptographic signature validation to prevent potential security control bypass. Defenders responsible for Pega Platform deployments sh [truncated]
A high-privileged user with a developer role can exploit a Stored Cross-site scripting (XSS) vulnerability in Pega Platform versions 23.1.0 through 25.1.3. This vulnerability affects the user interface component. The vulnerability requires verification of exposure and prioritization of remediation. Defenders responsible for Pega Platform deployments should assess their exposure and prioritize verification [truncated]
CVE-2025-62180 is an authorization weakness in Pega Platform versions 8.3.0 through Infinity 25.1.2. This vulnerability may allow authenticated users to access certain additional data via crafted URLs. The CVSS score for this vulnerability is 7.1, indicating a high severity. The CVE was published on June 23, 2026, and last modified on June 23, 2026. The vendor, Pega, has provided security advisories for t [truncated]