cloud foundry
Security Risk Profile
59
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 8, 2017 to present
22
Total CVEs
17
Critical+High
0
Exploited
17
Unpatched
Threat Assessment
Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
17
Critical/High
Risk Level
59/100
medium
Severity Distribution
Critical
4High
13Medium
5Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
OS Command Injection
2
2
Infoleak
2
3
Weak Encryption
1
4
Path Traversal
1
5
SQL Injection
1
Most Affected Products
1. Cloud Foundry Bosh20
2. Cloud Foundry UAA5
3. Cloud Foundry CF Deployment4
4. Cloud Foundry BOSH Director3
5. Cloud Foundry Diego3
Recent Vulnerabilities
See more →CVE-2026-47840
CVSS 9.3critical
LDAP StartTLS unconditionally disables hostname verification
7/9/2026🔧 No Patch
CVE-2026-41005
CVSS 9.0critical
UAA accepts SAML Encrypted Assertions authentication bypass
6/11/2026🔧 No Patch
CVE-2026-41010
CVSS 8.7high
6/4/2026🔧 No Patch
CVE-2026-41011
CVSS 8.7high
6/4/2026🔧 No Patch
CVE-2026-41859
CVSS 7.1high
6/4/2026🔧 No Patch
CVE-2026-41860
CVSS 7.1high
6/4/2026🔧 No Patch
CVE-2026-40965
CVSS 10.0critical
6/1/2026🔧 No Patch
CVE-2026-41704
CVSS 6.8medium
Compromised VM can make arbitrary blobstore deletes
5/27/2026🔧 No Patch
CVE-2026-41009
CVSS 4.3medium
Local Blobstore may allow arbitrary reads/deletes
5/27/2026🔧 No Patch
CVE-2026-22726
CVSS 5.0medium
Route Services Firewall Bypass
4/30/2026🔧 No Patch
Monitor cloud foundry in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.