c
cloud foundry
Security Risk Profile
61
/100
highSecurity Risk Score
Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 8, 2017 to present
23
Total CVEs
18
Critical+High
0
Exploited
18
Unpatched
Threat Assessment
Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
18
Critical/High
Risk Level
61/100
high
📈 1 in Last 30 Days
Severity Distribution
Critical
4High
14Medium
5Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
OS Command Injection
2
2
Infoleak
2
3
Command Injection
1
4
Weak Encryption
1
5
Path Traversal
1
Most Affected Products
1. Cloud Foundry Bosh20
2. Cloud Foundry UAA5
3. Cloud Foundry CF Deployment4
4. Cloud Foundry BOSH Director3
5. Cloud Foundry Diego3
Recent Vulnerabilities
See more →CVE-2026-47827
CVSS 7.5high
– BOSH CLI Powershell Injection
Aug 21, 2026🔧 No Patch
CVE-2026-47840
CVSS 9.3critical
LDAP StartTLS unconditionally disables hostname verification
Jul 9, 2026🔧 No Patch
CVE-2026-41005
CVSS 9.0critical
UAA accepts SAML Encrypted Assertions authentication bypass
Jun 11, 2026🔧 No Patch
CVE-2026-41010
CVSS 8.7high
Jun 4, 2026🔧 No Patch
CVE-2026-41011
CVSS 8.7high
Jun 4, 2026🔧 No Patch
CVE-2026-41859
CVSS 7.1high
Jun 4, 2026🔧 No Patch
CVE-2026-41860
CVSS 7.1high
Jun 4, 2026🔧 No Patch
CVE-2026-40965
CVSS 10.0critical
Jun 1, 2026🔧 No Patch
CVE-2026-41704
CVSS 6.8medium
Compromised VM can make arbitrary blobstore deletes
May 27, 2026🔧 No Patch
CVE-2026-41009
CVSS 4.3medium
Local Blobstore may allow arbitrary reads/deletes
May 27, 2026🔧 No Patch
Monitor cloud foundry in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.