Executive Summary - Action Required
Pega regularly implements security controls designed to safeguard client environments. As part of these efforts, Pega will release patch updates and hotfixes addressing one high-severity security vulnerability in Pega Platform.
No client compromises have been reported to date; however, remediation must be implemented to maintain security.
|
Advisory |
Description |
Patch Remediation |
Hotfix Remediation |
|---|---|---|---|
|
M26 |
Session API Security Vulnerability |
24.2.5 Patch Release (Released Jun 25 ‘26) 25.1.3 Patch Release (Released June 23 ‘26) 26.1 Patch Release (Released July 14 '26) |
HFIX-D1442 - 23.1.5 HFIX-D1279 - 24.1.4 HFIX-D1443 - 24.2.4 HFIX-D1416 - 25.1.2 |
Dates for upcoming patch releases can be found here: Pega Infinity Patch Calendar.
Information regarding the availability of the patch releases will be publicly posted on Pega Support Center August 10, 2026. We request that clients not discuss this in public forums until after this issue has been publicly posted to enable all customers to have adequate time to apply the necessary patches and/or hotfixes.
Impact
Improper validation of cryptographic signatures, such as insufficient checks to confirm that a request has been correctly signed and has not been altered, may allow an attacker to bypass security controls. This could enable unauthorized access to sensitive data or the ability to execute unauthorized actions.
Issue Details
|
Issue Details |
Session API Security Vulnerability |
|---|---|
|
Software/Product |
Pega Platform |
|
Affected Version(s) |
From 8.5 to 25.1.2 |
|
CVE |
CVE-2026-10754 |
|
CVSS Rating |
High – 7.6 |
|
Description |
Session API Security Vulnerability |
As a best practice, you should update your Pega environment to the latest release to take advantage of the latest features, capabilities, security, and bug fixes. See Keeping Current with Pega for details.
Obtaining your Hotfixes
Hotfixes are being created only for the patch releases listed above, under Hotfix Remediation. A restart is needed after hotfix installation.
We will not provide hotfixes on prior versions of Pega Platform.
-
Pega Cloud® and United States Pega Cloud for Government (PCFG) clients, using the versions listed above, will have hotfixes applied proactively, with Cloud Maintenance (CM) cases detailing the schedule. If you are not on a version with a solution provided, please update promptly.
-
On-premises or client-managed cloud clients should check the table above for applicable hotfixes and download them directly from My Security Hotfixes on My Pega.
If you have questions or concerns, please raise a Support Ticket in My Support Portal.