# CVE-2026-56454

## Summary

- **CVE ID:** CVE-2026-56454
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-327
- **Published:** Jul 16, 2026
- **Last Modified:** Jul 16, 2026

## Description

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.

## Affected Products

- HCL Software — DFXAnalytics (version 3.0 and below)

## References

- [CNA](https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._