Skip to content
English

Products › Brands

Brand

Mitel: actively exploited vulnerabilities

7 vulnerabilities in Mitel products (MiCollab, MiVoice Connect, SIP Phones (6800 / 6900)) are in CISA’s catalog of exploited vulnerabilities. Last added: February 12, 2025.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Mitel category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • MiCollab 3 vulnerabilities · Collaboration and video
  • MiVoice Connect 3 vulnerabilities · Collaboration and video
  • SIP Phones (6800 / 6900) 1 vulnerability · Collaboration and video

Name used by CISA: Mitel. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Mitel list.

  1. Rank 1Mitel MiVoice Connect

    CVE-2022-29499

    Ransomware

    Mitel MiVoice Connect Data Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Mitel MiCollab

    CVE-2022-26143

    MiCollab, MiVoice Business Express Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Mitel MiCollab

    CVE-2024-41713

    Ransomware

    Mitel MiCollab Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  4. Rank 4Mitel SIP Phones (6800 / 6900)

    CVE-2024-41710

    Mitel SIP Phones Argument Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 12, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  5. Rank 5Mitel MiVoice Connect

    CVE-2022-40765

    Ransomware

    Mitel MiVoice Connect Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  6. Rank 6Mitel MiVoice Connect

    CVE-2022-41223

    Ransomware

    Mitel MiVoice Connect Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  7. Rank 7Mitel MiCollab

    CVE-2024-55550

    Ransomware

    Mitel MiCollab Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    2.7 (low)

Follow and verify

Get new Mitel vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.