CVE-2026-15806: `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Aug
Released
2026-08-21
EPSS Score
0.43% (percentile: 36.1%)

Affected Products (2)

Other

  • 21021-17084
  • 21694-17084

Revision History

  • 2026-08-21: Information published.