CVE-2025-31980

HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems.

  • Published Oct 1, 2026
  • CVSS 4.3 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2025-31980 at the National Vulnerability Database