Where
-Infinity
0

CyberArk Endpoint Privilege Manager AgentCyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized pr…

Risk 54
Severity
8.5
EPSS
0.01%
First published (updated )

CyberArk Endpoint Privilege ManagementZDI-26-059: CyberArk Endpoint Privilege Management Improper Privilege Management Local Privilege Escalation Vulnerability

Risk 35
First published (updated )

CyberArk Endpoint Privilege ManagementCyberArk Endpoint Privilege Management Improper Privilege Management Local Privilege Escalation Vulnerability

Risk 35
First published (updated )
Advisory
ZDI-26-059

CyberArk Endpoint Privilege Manager AgentCyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege e…

Risk 69
Severity
7.8
First published (updated )

CyberArk Secure Web Sessions ExtensionClient-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305

Risk 22
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Five new CVEs published for Cyberark Conjur OSS

First published (updated )

Five new CVEs published for Cyberark Conjur OSS

First published (updated )

CyberArk ConjurConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via Mis-configured Network Device

Risk 90
Severity
9.8
First published (updated )

CyberArk ConjurConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to path traversal and file disclosure

Risk 43
Severity
7.1
First published (updated )

CyberArk ConjurConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) missing validations

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CyberArk ConjurConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code Execution

Risk 83
Severity
8.8
First published (updated )

CyberArk ConjurConjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator

Risk 90
Severity
9.8
First published (updated )

CyberArk Endpoint Privilege ManagerHTML injection in CyberArk Endpoint Privilege Manager

Risk 22
Severity
2
First published (updated )

CyberArk Endpoint Privilege ManagerLack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege Manager

Risk 67
Severity
9.3
First published (updated )

CyberArk Endpoint Privilege ManagerSelf Reflected XSS in CyberArk Endpoint Privilege Manager

Risk 21
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CyberArk Endpoint Privilege ManagerIP Spoofing in CyberArk Endpoint Privilege Manager

Risk 41
Severity
6.9
First published (updated )

CyberArk Endpoint Privilege ManagerStored XSS in CyberArk Endpoint Privilege Manager

Risk 62
Severity
7.3
First published (updated )

CyberArk Privileged Access Manager Self-HostedPVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does …

Risk 38
Severity
6.1
First published (updated )

CyberArk Privileged Access Manager Self-HostedPVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has p…

Risk 29
Severity
4.2
First published (updated )

CyberArk IdentityCyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

Risk 69
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CyberArk IdentityCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Risk 22
Severity
4.3
First published (updated )

CyberArk IdentityCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Risk 22
Severity
4.3
First published (updated )

CyberArk IdentityCyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Risk 38
Severity
6.5
First published (updated )

CyberArk ViewfinityIn CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an a…

Risk 69
Severity
7.8
First published (updated )

CyberArk IdentityCyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes t…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CyberArk Endpoint Privilege Manager WindowsCyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user t…

Risk 69
Severity
7.8
First published (updated )

CyberArk Credential ProviderAn inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may le…

Risk 43
Severity
7.5
First published (updated )

CyberArk Credential ProviderThe effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has …

Risk 26
Severity
4.4
First published (updated )

CyberArk Credential ProviderRace Condition

Risk 30
Severity
5.1
First published (updated )

CyberArk IdentityCyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals wheth…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203