Nexus Repository Manager
69 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Nexus Repository Manager, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Nexus Repository Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 3 |
| 2026-05 | 2 |
| 2026-06 | 3 |
| 2026-07 | 5 |
| 2026-08 | 11 |
| 2026-09 | 4 |
Severity
How the 69 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High29
- Medium33
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Nexus Repository Manager.
- CVE-2026-77125Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints7.1
- CVE-2026-77124Nexus Repository 3 - Script Execution Disable Setting Not Enforced7.2
- CVE-2026-77122Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metadata via Group Repository Permissions4.3
- CVE-2026-77123Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API6.5
- CVE-2026-17594Nexus Repository 3 - Authorization Bypass in Repository Creation4.9
- CVE-2026-17595Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass2.7
- CVE-2026-17593Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration7.2
- CVE-2026-14644Nexus Repository 3 - Privilege Escalation7.2
- CVE-2026-17601Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator7.2
- CVE-2026-17598Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration4.9
- CVE-2026-17600Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation8.8
- CVE-2026-17596Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name6.1
- CVE-2026-17599Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint7.2
- CVE-2026-17597Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification2.7
- CVE-2026-17603Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API8.8
Product grouping is registry-driven, with AI assist and human review. How it works