CVE-2026-46398 - HAX CMS Missing Secure Flag on Cookie
CVE ID :CVE-2026-46398 Published : June 5, 2026, 8:17 p.m. | 57 minutes ago Description :HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_token cookie is set without the Secure flag. This allows it...