SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-11756

CRITICAL · CVSS 10 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The Station Launcher App within the 3DEXPERIENCE platform is vulnerable to a critical deserialization of untrusted data flaw, allowing unauthenticated remote code execution. This vulnerability affects versions from R2023x to R2026x, posing a significant risk to any organization utilizing these releases. Organizations using the 3DEXPERIENCE platform should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-11756
Severity
CRITICAL
CVSS
10
EPSS
0.45%

Original NVD Description

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.