SecAlerts
p

pega

Security Risk Profile

41
/100
medium

Security Risk Score

Comprehensive risk assessment based on 57 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 2, 2017 to present

57
Total CVEs
24
Critical+High
0
Exploited
24
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
24
Critical/High
Risk Level
41/100
medium
🆕 1Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
8
High
16
Medium
33
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
30
2
Malicious File Upload
1
3
Code Injection
1
4
XEE
1
5
SSRF
1

Most Affected Products

1. Pega Pega Platform65
2. Pega Infinity13
3. Pega Platform12
4. PEGA Infinity8
5. Pegasystems Pega Platform3

Recent Vulnerabilities

See more →
CVE-2026-13761
CVSS 8.8high

Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Aug 28, 2026🔧 No Patch
CVE-2026-10754
CVSS 8.6high

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

Aug 10, 2026🔧 No Patch
CVE-2026-14337
CVSS 4.6medium

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

Aug 4, 2026🔧 No Patch
CVE-2026-1563
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

Jul 15, 2026🔧 No Patch
CVE-2026-1562
CVSS 4.6medium

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

Jul 15, 2026🔧 No Patch
CVE-2026-1711
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.

Apr 15, 2026🔧 No Patch
CVE-2026-1564
CVSS 5.1medium

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.

Apr 15, 2026🔧 No Patch
CVE-2026-1078
CVSS 7.2high

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge.

Apr 7, 2026🔧 No Patch
CVE-2025-62184
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.

Mar 31, 2026🔧 No Patch
CVE-2025-62183
CVSS 4.8medium

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.

Feb 17, 2026🔧 No Patch

Monitor pega in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

pega Security Vulnerabilities & Risk Score | 57 CVEs | SecAlerts - SecAlerts