CVE Tools

Gateway

90 CVEs tracked. 6 of them are in CISA KEV.

This hub aggregates every CVE we track for Gateway, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

Gateway CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gateway CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-011
2025-020
2025-031
2025-040
2025-050
2025-062
2025-070
2025-083
2025-090
2025-100
2025-111
2025-121
2026-011
2026-020
2026-033
2026-040
2026-050
2026-066
2026-070
2026-083
2026-097

Severity

How the 90 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1618%
  • High3843%
  • Medium3439%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gateway.

  1. CVE-2026-53714Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway operates in GatewayNamespaceMode7.4
  2. CVE-2026-53716Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit6.5
  3. CVE-2026-53715Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock5.3
  4. CVE-2026-53719Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization6.5
  5. CVE-2026-53718Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass6.4
  6. CVE-2026-53713Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure9.1
  7. CVE-2026-53717Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header6.5
  8. CVE-2026-82270Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*7.5
  9. CVE-2026-19490NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-194909.8
  10. CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.—
  11. CVE-2026-13474Denial of service via malformed HTTP/2 requests7.5
  12. CVE-2026-10817Insufficient input validation leading to memory overread7.5
  13. CVE-2026-10816Arbitrary File Read (Unauthenticated)7.5
  14. CVE-2026-8655Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service9.8
  15. CVE-2026-8452Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store