CVE Tools

Authenticator

13 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Authenticator, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Authenticator CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Authenticator CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-120
2026-010
2026-020
2026-033
2026-040
2026-051
2026-060
2026-070
2026-080
2026-091

Severity

How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical215%
  • High538%
  • Medium431%
  • Low215%

Latest CVEs

The 13 most recently published vulnerabilities affecting Authenticator.

  1. CVE-2026-80097Microsoft Authenticator Elevation of Privilege Vulnerability8.6
  2. CVE-2026-41615Microsoft Authenticator Information Disclosure Vulnerability9.6
  3. CVE-2026-33875Authenticator Vulnerable to Authentication Flow Hijack9.3
  4. CVE-2026-33874Authenticator vulnerable to Remote Code Execution7.8
  5. CVE-2026-26123Microsoft Authenticator Information Disclosure Vulnerability5.5
  6. CVE-2025-54154QNAP Authenticator6.8
  7. CVE-2024-45394Secret encryption vulnerable to brute-force attacks8.8
  8. CVE-2024-21390Microsoft Authenticator Elevation of Privilege Vulnerability7.1
  9. CVE-2023-27895Information Disclosure vulnerability in SAP Authenticator for Android6.1
  10. CVE-2022-3994Authenticator < 1.3.1 - Subscriber+ Denial of Service via Feed Token Disclosure4.3
  11. CVE-2022-35290Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.7.5
  12. CVE-2021-25266An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, a...3.9
  13. CVE-2012-6140pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictio...1.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store