Skip to content
English

Products › IT administration and security

IT administration and security

Security products

Antivirus, EDR, SIEM, sandboxes and other security tools: attackers target them too.

For example: Microsoft Defender, Trend Micro, FortiSandbox, Splunk.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Fortinet 2 vulnerabilities · 2 in the last 12 months
  • Fortra 2 vulnerabilities
  • IBM 3 vulnerabilities
  • McAfee 1 vulnerability
  • Microsoft 6 vulnerabilities · 3 in the last 12 months
  • Sophos 1 vulnerability
  • Splunk 1 vulnerability · 1 in the last 12 months
  • TeamT5 1 vulnerability · 1 in the last 12 months
  • Trend Micro 12 vulnerabilities · 1 in the last 12 months
  • Wazuh 1 vulnerability

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Fortinet FortiSandbox

    CVE-2026-25089

    Hunt for compromise (CISA)

    Fortinet FortiSandbox OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Fortinet FortiSandbox

    CVE-2026-39808

    Hunt for compromise (CISA)

    Fortinet FortiSandbox OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Splunk Enterprise

    CVE-2026-20253

    Splunk Enterprise Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Microsoft Defender

    CVE-2026-41091

    Microsoft Defender Link Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  5. Rank 5Microsoft Defender

    CVE-2026-33825

    Ransomware

    Microsoft Defender Insufficient Granularity of Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 22, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  6. Rank 6Microsoft Defender

    CVE-2026-45498

    Microsoft Defender Denial of Service Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  7. Rank 7TeamT5 ThreatSonar Anti-Ransomware

    CVE-2024-7694

    CVE from 2024, added in 2026

    TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  8. Rank 8Trend Micro Apex One (ex-OfficeScan)

    CVE-2026-34926

    Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 21, 2026
    CISA deadline
    14 days
    CVSS severity
    6.7 (medium)
  9. Rank 9Wazuh Server

    CVE-2025-24016

    Wazuh Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 10, 2025
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  10. Rank 10Trend Micro Apex One (ex-OfficeScan)

    CVE-2025-54948

    Trend Micro Apex One OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 20 more vulnerabilities
  1. Rank 11Sophos Web Appliance

    CVE-2023-1671

    Sophos Web Appliance Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Fortra Cobalt Strike

    CVE-2022-42948

    Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Trend Micro Apex Central

    CVE-2022-26871

    Trend Micro Apex Central Arbitrary File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14IBM Data Risk Manager

    CVE-2020-4427

    IBM Data Risk Manager Security Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-8599

    Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  6. Rank 16IBM Data Risk Manager

    CVE-2020-4428

    IBM Data Risk Manager Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  7. Rank 17Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-8467

    Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  8. Rank 18Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-8468

    Trend Micro Multiple Products Content Validation Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  9. Rank 19Trend Micro Apex One (ex-OfficeScan)

    CVE-2021-36741

    Trend Micro Multiple Products Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  10. Rank 20Microsoft Defender

    CVE-2017-8540

    CVE from 2017, added in 2022

    Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  11. Rank 21Trend Micro Apex One (ex-OfficeScan)

    CVE-2020-24557

    Trend Micro Multiple Products Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  12. Rank 22Microsoft Defender

    CVE-2021-1647

    Microsoft Defender Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  13. Rank 23McAfee Total Protection (MTP)

    CVE-2021-23874

    McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  14. Rank 24Trend Micro Apex One (ex-OfficeScan)

    CVE-2021-36742

    Trend Micro Multiple Products Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  15. Rank 25Trend Micro Apex One (ex-OfficeScan)

    CVE-2019-18187

    CVE from 2019, added in 2021

    Trend Micro OfficeScan Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  16. Rank 26Trend Micro Apex One (ex-OfficeScan)

    CVE-2023-41179

    Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 21, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  17. Rank 27Trend Micro Apex One (ex-OfficeScan)

    CVE-2022-40139

    Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  18. Rank 28Fortra Cobalt Strike

    CVE-2022-39197

    Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  19. Rank 29Microsoft Defender

    CVE-2022-44698

    Ransomware

    Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  20. Rank 30IBM Data Risk Manager

    CVE-2020-4430

    IBM Data Risk Manager Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.