HCL disclosed two high-severity vulnerabilities affecting HCL Aftermarket DPC and the HCL BigFix Platform, with both issues exposing organizations to significant compromise risk. CVE-2025-55261 affects HCL Aftermarket DPC and is described as Missing Functional Level Access Control (CWE-284), a flaw that could let an attacker escalate privileges, compromise the application, and steal or manipulate data. The issue carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H, indicating network exposure with high impact to confidentiality and availability.
HCL also reported CVE-2026-21765 in the HCL BigFix Platform, where insecure permissions on private cryptographic keys stored on Windows hosts could expose sensitive keys to local users. The weakness maps to CWE-276 and CWE-732, reflecting incorrect default permissions and improper permission assignment for critical resources, and received a CVSS v3.1 vector of AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Together, the disclosures highlight risks from weak access controls and improperly protected cryptographic material in enterprise HCL software, with HCL directing customers to its support advisories for remediation details.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-02, a new vulnerability, CVE-2026-21765, was reported for the HCL BigFix Platform. The issue involves insecure permissions on private cryptographic keys on Windows hosts, potentially exposing keys because of overly permissive file system permissions.
HCL's PSIRT received CVE-2025-55261 on 2026-03-26 for a Missing Functional Level Access Control flaw in HCL Aftermarket DPC. The vulnerability could allow privilege escalation, application compromise, and theft or manipulation of data, and HCL published a support advisory for additional details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.