CVE-2026-15806: `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
Overview
- Severity
- N/A
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-21
- Last Updated
- 2026-10-02
- EPSS Score
- 0.46% (percentile: 38.1%)
Affected Products (4)
Other
- 21021-17084
- 21694-17084
- 21811-17084
- 21897-17084
Security Updates (1)
Revision History
- 2026-08-21: Information published.
- 2026-09-09: Information published.
- 2026-09-11: Information published.
- 2026-09-23: Information published.
- 2026-09-25: Information published.
- 2026-10-02: Information published.