VDB

CVE-2026-0500

CVE-2026-0500 PUBLISHED CVSS 9.600000381469727 CRITICAL

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.

EPSS 0.17% · 38.5th percentile

Risk Scores

CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
0.17%
38.5th percentile

Affected Products

VendorProductVersions
SAP_SESAP Wily Introscope Enterprise Manager (WorkStation)WILY_INTRO_ENTERPRISE 10.8, WILY_INTRO_ENTERPRISE 10.8
sapintroscope_enterprise_manager10.8, 10.8, 10.8

Timeline

  • Jan 13, 2026 EPSS Score
  • Jan 13, 2026 CVE Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 14, 2026 PoC Published
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›