CVE-2026-11747

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.

  • Published Aug 27, 2026
  • CVSS 6.1 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-11747 at the National Vulnerability Database