SecAlerts
A

Academy Software Foundation

Security Risk Profile

68
/100
high

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 8, 2024 to present

13
Total CVEs
10
Critical+High
0
Exploited
10
Unpatched

Threat Assessment

Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
68/100
high

Severity Distribution

Critical
0
High
10
Medium
0
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
3
2
Integer Overflow
2

Most Affected Products

1. Academy Software Foundation OpenEXR22
2. OpenEXR OpenEXR7

Recent Vulnerabilities

See more →
CVE-2026-40244
CVSS 8.4high

OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)

Apr 21, 2026🔧 No Patch
CVE-2025-12840
CVSS 7.8high

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Dec 23, 2025🔧 No Patch
CVE-2025-12839
CVSS 7.8high

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Dec 23, 2025🔧 No Patch
CVE-2025-12495
CVSS 7.8high

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Dec 23, 2025🔧 No Patch
ZDI-CAN-27947
CVSS 7.8high

ZDI-25-990: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Nov 11, 2025🔧 No Patch
ZDI-CAN-27948
CVSS 7.8high

ZDI-25-991: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Nov 11, 2025🔧 No Patch
ZDI-25-990
CVSS 7.8high

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Nov 11, 2025🔧 No Patch
ZDI-CAN-27946
CVSS 7.8high

ZDI-25-989: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Nov 11, 2025🔧 No Patch
ZDI-25-989
CVSS 7.8high

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Nov 11, 2025🔧 No Patch
ZDI-25-991
CVSS 7.8high

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Nov 11, 2025🔧 No Patch

Monitor Academy Software Foundation in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Academy Software Foundation Security Vulnerabilities & Risk Score | 13 CVEs | SecAlerts - SecAlerts