CERT Polska disclosed three vulnerabilities in Dayforce Payroll version R2026.2.0: an unauthenticated time-based blind SQL injection in password recovery (CVE-2026-73640), reflected cross-site scripting affecting multiple endpoints (CVE-2026-73641), and an unauthenticated path-traversal flaw in file-download functionality (CVE-2026-73642). The flaws could enable unauthorized database inference, script execution in users’ browsers, and access to files outside intended download paths.
The issues were reported by researcher Dawid Dudek, known as 4c1d8urn, and disclosure was coordinated by CERT Polska. CERT Polska said it was unable to establish contact with the vendor, so testing and confirmation were limited to R2026.2.0; other Dayforce Payroll releases may also be affected. Organizations using the product should identify exposed instances, restrict public access where feasible, monitor password-recovery and download endpoints for anomalous requests, and seek vendor remediation or compensating controls.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
CERT Polska published advisories for CVE-2026-73640, CVE-2026-73641, and CVE-2026-73642, confirmed in Dayforce Payroll R2026.2.0. The flaws comprise unauthenticated time-based blind SQL injection in password recovery, reflected XSS across multiple endpoints, and unauthenticated path traversal in file downloads; CERT Polska said vendor contact attempts were unsuccessful.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.