CRITICAL 10.0 NVD
CVE-2026-22306
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnera
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.
References
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-08-19 via NVD.
Risk Timeline
CVE Disclosed2026-08-19 · 0 days ago
Remediation Resources
Official Advisory
offseq.com/en/research/ozols-cve-2026-22306
vulnfeed aggregates 11672 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.