CVE-2026-13462: exploitation status and patch state
CVE-2026-13462 · CVSS 7.5 HIGH · EPSS <1%
PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
Is CVE-2026-13462 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.