PatchSiren

Septeo IT Solutions CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Septeo IT Solutions CVE published 2026-09-02

CVE-2026-75137

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. The vulnerability is caused by the application's failure to properly secure sensitive data in memory, allowing attackers with PROCESS_VM_READ permission to access and extract sensitive information. Th [truncated]

MEDIUM Septeo IT Solutions CVE published 2026-09-02

CVE-2026-75136

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T20:17:36.877Z and has not been modified since then. UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any authentication prompt. This [truncated]

MEDIUM Septeo IT Solutions CVE published 2026-09-02

CVE-2026-75135

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T20:17:36.720Z and has not been modified since then. UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe. T [truncated]