A critical vulnerability (CVE-2026-40175) in the Axios JavaScript library (versions prior to 1.15.0) can allow Prototype Pollution attacks to escalate into Remote Code Execution or Full Cloud Compromise.
Users should upgrade to version 1.15.0 immediately, and WithSecure Policy Manager customers should apply the available hotfix from the WithSecure Download Center as a priority.
Read the full article here:
https://community.withsecure.com/announcements-en/kb/articles/32898-cve-2026-40175-for-axios-javascript-library