CVE-2026-14466
It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
- Published Sep 4, 2026
- CVSS 4.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)