cve-2026-21404

  1. NAVTOR NavBox WCF SOAP Hard-Coded Credentials (CVE-2026-21404) Fix

    CISA published ICSA-26-155-01 on June 4, 2026, warning that NAVTOR NavBox 4.16.1.20 contains hard-coded credentials in its Windows Communication Foundation SOAP implementation, allowing a local authenticated attacker to reach privileged methods if SOAP is enabled. The bug is not a remote...