STER software patches three vulnerabilities
STER software had a SQL injection, weak password encoding, and unencrypted TCP traffic flaws, all fixed in version 9.5.
CERT Polska coordinated disclosure of three vulnerabilities in STER software, reported by Michelin CERT. CVE-2026-25606 is a SQL injection vulnerability in the application's Search Filters that allows an authenticated attacker to access sensitive data belonging to other users or any data the application can reach. CVE-2026-25607 involves use of a weak password encoding algorithm, which could allow an attacker to derive password values by analyzing how known passwords are encoded. CVE-2026-25608 stems from STER's use of unencrypted TCP traffic to transmit data, exposing passwords, personal data, and authentication tokens to Man-in-the-Middle attacks.
All three issues were addressed in STER version 9.5. There is no indication in the advisory of active exploitation in the wild; this is a standard responsible disclosure and patch notice rather than evidence of an ongoing attack campaign.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-25606
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free