CVE-2026-40118: Medium severity Arcserve Arcserve UDP Console vulnerability
UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40118?
CVE-2026-40118 has a moderate severity level due to the risk of unintentional data communication.
How do I fix CVE-2026-40118?
To fix CVE-2026-40118, ensure that the activation server hostname is set to a valid and trusted URL.
What software is affected by CVE-2026-40118?
The affected software includes Arcserve Arcserve UDP Console.
What can happen if I leave the vulnerability CVE-2026-40118 unaddressed?
Leaving CVE-2026-40118 unaddressed may lead to unauthorized information disclosure to a dummy domain.
Is there a patch available for CVE-2026-40118?
Currently, there is no specific patch mentioned for CVE-2026-40118, and users must manually configure settings.