SecAlerts
A

Altium

Security Risk Profile

66
/100
high

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 15, 2026 to present

20
Total CVEs
17
Critical+High
0
Exploited
17
Unpatched

Threat Assessment

Avg CVSS
8.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
17
Critical/High
Risk Level
66/100
high

Severity Distribution

Critical
12
High
5
Medium
3
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
8

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
9
2
XSS
6
3
Infoleak
3
4
Malicious File Upload
2
5
Code Injection
1

Most Affected Products

1. Altium On-prem Enterprise Server7
2. Altium Altium 3656
3. Altium Altium Enterprise Server5
4. Altium Altium Live3
5. Altium Altium Enterprise Server 8.1.11

Recent Vulnerabilities

See more →
CVE-2026-14439
CVSS 9.4critical

Path Traversal in Altium Git Service Allows Remote Code Execution

Jul 1, 2026🔧 No Patch
CVE-2026-11431
CVSS 8.3high

Path Traversal in Altium Projects Service Allows Arbitrary File Read

Jun 5, 2026🔧 No Patch
CVE-2026-11429
CVSS 10.0critical

Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execution

Jun 5, 2026🔧 No Patch
CVE-2026-11424
CVSS 8.3high

Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information Disclosure

Jun 5, 2026🔧 No Patch
CVE-2026-11423
CVSS 9.4critical

Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation

Jun 5, 2026🔧 No Patch
CVE-2026-11420
CVSS 10.0critical

Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Read

Jun 5, 2026🔧 No Patch
CVE-2026-11419
CVSS 9.4critical

Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write

Jun 5, 2026🔧 No Patch
CVE-2026-11414
CVSS 10.0critical

Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path Traversal

Jun 5, 2026🔧 No Patch
CVE-2026-9152
CVSS 10.0EPSS 0%critical

Unauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant Data Exfiltration and Index Destruction

May 21, 2026🔧 No Patch
CVE-2026-9129
CVSS 9.4EPSS 0%critical

Path Traversal in Altium Enterprise Server Viewer StorageController Allows Arbitrary File Read

May 20, 2026🔧 No Patch

Monitor Altium in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Altium Security Vulnerabilities & Risk Score | 20 CVEs | SecAlerts - SecAlerts