Vulnerability Description
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN88396700/
- https://support.arcserve.com/s/article/P00003790?language=en_US&r=94&ui-knowledg
FAQ
What is CVE-2026-40118?
CVE-2026-40118 is a vulnerability with a CVSS score of 6.3 (MEDIUM). UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to...
How severe is CVE-2026-40118?
CVE-2026-40118 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40118?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.