CVE Tools

Arc

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Arc, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Arc CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Arc CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-087
2026-092

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical210%
  • High945%
  • Medium630%
  • Low315%

Latest CVEs

The 15 most recently published vulnerabilities affecting Arc.

  1. CVE-2026-94181Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element7.4
  2. CVE-2026-33389Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.07.5
  3. CVE-2026-55678Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset—
  4. CVE-2026-48106Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer—
  5. CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive—
  6. CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks—
  7. CVE-2026-48050Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS—
  8. CVE-2026-33922Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.06.0
  9. CVE-2026-33921Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.05.2
  10. CVE-2025-40896Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.06.5
  11. CVE-2024-52928Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.9.6
  12. CVE-2024-45489Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to ...9.8
  13. CVE-2023-5938Path traversal via 'zip slip' in Arc before v1.6.08.0
  14. CVE-2023-5937Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.03.8
  15. CVE-2023-5936Unsafe temporary data privileges on Unix systems in Arc before v1.6.07.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store