PatchSiren

wibu-systems-ag CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wibu-systems-ag CVE published 2026-08-27

CVE-2026-81576

The CVE-2026-81576 vulnerability affects CodeMeter Runtime when configured as a server, specifically before versions 8.41a and 9.10. It involves a cryptographically weak SID used as the sole authenticator, allowing potential brute-force attacks to recover session handle numbers and read license information belonging to other handles. Organizations should be aware of this vulnerability and take steps to mi [truncated]

HIGH wibu-systems-ag CVE published 2026-08-27

CVE-2026-81572

The CodeMeter Runtime, specifically versions 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, contains a local privilege escalation vulnerability. This issue arises from the creation of a predictable temporary file under C:CM-Stick, where directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local atta [truncated]