CVE-2026-66372
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
- Published Sep 15, 2026
- CVSS 7.6 high
- 0.3% chance of exploitation in the next 30 days (EPSS)