๐Ÿ” CVE Alert

CVE-2026-10726

UNKNOWN 0.0

Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

CWE CWE-295 CWE-73
Vendor cato networks
Product sdp client
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for cato networks sdp client

Be the first to know when new unknown vulnerabilities affecting cato networks sdp client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Cato Networks / SDP Client
0 < 6.12.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
knowledge.catonetworks.com: https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126