Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Click Studios’ September 28, 2026 advisory reports multiple high-severity CVEs in Passwordstate Core and says they are fixed in Build 10142. The vendor has not yet published the CVE identifiers, affected-version range, technical details, or exploit conditions, so administrators cannot determine from the announcement alone whether a particular earlier build is affected. Check your installed build and follow the vendor’s upgrade guidance while monitoring the advisory for details.
What are the Passwordstate vulnerabilities?
Click Studios’ security advisory lists a September 28, 2026 entry for multiple Passwordstate Core CVEs, rates them High, and marks details as pending. The vendor’s V10 changelog dates Build 10142 to September 28 and says it contains multiple security updates, with CVEs pending.
The published information does not identify the new CVEs or explain which earlier builds are affected, how an attacker might exploit them, what the impact is, or whether a particular deployment configuration is exposed. The vendor’s current rating is High; the announcement does not substantiate describing the individual issues as confirmed critical vulnerabilities.
Which Passwordstate build fixes the vulnerabilities?
Click Studios lists Passwordstate Build 10142 as the fix for the September 28 announcement. Administrators should identify their installed version and build, then compare it with the vendor’s current release and advisory information and use Click Studios’ documented upgrade process for their deployment. Because affected-version details are pending, the announcement alone does not establish whether a particular earlier build is affected.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Check the advisory again for later technical details before making version-specific exposure decisions. The currently published information does not provide a workaround, indicators of compromise, or other mitigation steps for these new CVEs.
What earlier Passwordstate vulnerabilities show about build scope?
Past advisories affect different product areas and have distinct fixed-build boundaries. Those records provide context, but they do not establish that an older vulnerability remains exploitable in a current build or reveal the pending details of the 2026 announcement.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| CVE and date | Area and published details | Fixed build |
|---|---|---|
| CVE-2025-59453 August 28, 2025 |
Passwordstate Core; High severity. NVD describes an authentication bypass in which a crafted URL used on the Emergency Access page could let an unauthorized person reach the Administration section. Affected before Passwordstate 9.9 Build 9972. | Build 9972 |
| CVE-2024-54124 November 25, 2024 |
Permission escalation on the edit-folder screen; vendor severity Low. NVD describes the affected range as before Build 9920. | Build 9920 |
| CVE-2024-39337 March 7, 2024 |
Passwordstate Core; vendor severity High and potential authentication bypass. NVD describes Passwordstate Core before 9.8 Build 9858 as affected. | Build 9858 |
| CVE-2020-26061 October 5, 2020 |
Password Reset Portal before Build 8501. NVD describes a ResetPassword function that did not validate successful authentication using security questions before accepting a crafted HTTP request to set a registered user’s password. | Build 8501 |
Sources for the historical entries: Click Studios’ security advisory; NVD records for CVE-2025-59453, CVE-2024-54124, CVE-2024-39337, and CVE-2020-26061.
How should administrators assess their exposure?
- Identify the installation: Record the Passwordstate version and build in use and determine which product areas or modules are deployed.
- Check the current vendor information: Compare the installed build with the Click Studios advisory and the release notes. For the September 28, 2026 announcement, Build 10142 is the listed fix.
- Upgrade using the documented process: Follow the vendor’s instructions for your deployment rather than assuming a historical CVE’s affected range or module applies to this announcement.
- Recheck for details: The new entries’ identifiers, affected ranges, exploit conditions, impact, and any additional mitigation were pending in the advisory information reviewed September 30, 2026.
Is my Passwordstate version affected?
The published September 28 announcement does not yet provide the affected-version range, so it cannot answer that question for a specific pre-10142 installation. Build 10142 is identified as fixed, but that alone does not define which earlier builds are vulnerable. For older CVEs, assess only the product area and version range stated in the individual advisory and NVD record.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Rank #4
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

