Description
HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.
Published: 2026-07-21
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL MyCloud includes an IIS Server component that suffers from a known vulnerability, corresponding to CWE‑1104, and may expose the system to publicly disclosed weaknesses. Failure to exclude or remediate these weaknesses can allow an attacker to compromise the server, affecting confidentiality, integrity, or availability of the platform.

Affected Systems

HCL Software MyCloud installations are affected; specific versions are not listed in the available data.

Risk and Exploitability

The CVSS score of 2.2 indicates a low overall severity, and the EPSS score of less than 1% suggests a very low likelihood of immediate exploitation. The vulnerability is not listed in on the nature of the IIS Server component, the likely attack vector is remote and requires publicly reachable web services. The exploitation would depend on the presence of known IIS weaknesses and does not appear to have been leveraged in the wild or in documented attacks at the time of this report.

Generated by OpenCVE AI on August 1, 2026 at 06:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft IIS security patches to the affected MyCloud servers.
  • Restrict inbound traffic to the IIS hosts with firewall rules limiting access to trusted IP ranges.
  • Disable any unused IIS modules and remove default or unused web pages to reduce the attack surface.
  • Continuously monitor IIS logs for anomalous requests and maintain audit logging to detect potential exploitation attempts.

Generated by OpenCVE AI on August 1, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware mycloud
Vendors & Products Hclsoftware
Hclsoftware mycloud

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.
Title HCL MyCloud was affected by Using Components with Known Vulnerability
Weaknesses CWE-1104
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Mycloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:26:35.626Z

Reserved: 2026-06-22T13:39:47.964Z

Link: CVE-2026-56580

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:45.456Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:00:04Z

Weaknesses
  • CWE-1104

    Use of Unmaintained Third Party Components