Hosted hereSecurity ResearchReverse EngineeringVulnerability Disclosure
CVE-2026-92680: DPAPI Without Entropy in Araxis Merge
Tracked as CVE-2026-92680: Araxis Merge stored server credentials behind a single DPAPI call with no entropy, recoverable in plaintext by any process running as the user. Affected every release from 2011 to 2026.