Multiple Cross-Site Scripting Vulnerabilities Discovered in Web Applications

Multiple Cross-Site Scripting Vulnerabilities Discovered in Web Applications

First seen 21 Feb 2026, 09:17 UTC TenableFeedlyApi.Msrc.MicrosoftNvd.Nistwww.incibe.es+5 35.1

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities have been identified in various web applications, including SVXportal and Dell Unisphere for PowerMax. These vulnerabilities allow unauthenticated remote attackers to inject and execute arbitrary JavaScript in victims' browsers, potentially leading to session theft and information disclosure. The vulnerabilities were published between February 17 and February 20, 2026.

Timeline

2026-02-17
CVE-2026-26357 published
2026-02-19
CVE-2025-15562 published
2026-02-20
CVE-2026-27502 published