Authenticator
13 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Authenticator, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Authenticator CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High5
- Medium4
- Low2
Latest CVEs
The 13 most recently published vulnerabilities affecting Authenticator.
- CVE-2026-80097Microsoft Authenticator Elevation of Privilege Vulnerability8.6
- CVE-2026-41615Microsoft Authenticator Information Disclosure Vulnerability9.6
- CVE-2026-33875Authenticator Vulnerable to Authentication Flow Hijack9.3
- CVE-2026-33874Authenticator vulnerable to Remote Code Execution7.8
- CVE-2026-26123Microsoft Authenticator Information Disclosure Vulnerability5.5
- CVE-2025-54154QNAP Authenticator6.8
- CVE-2024-45394Secret encryption vulnerable to brute-force attacks8.8
- CVE-2024-21390Microsoft Authenticator Elevation of Privilege Vulnerability7.1
- CVE-2023-27895Information Disclosure vulnerability in SAP Authenticator for Android6.1
- CVE-2022-3994Authenticator < 1.3.1 - Subscriber+ Denial of Service via Feed Token Disclosure4.3
- CVE-2022-35290Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.7.5
- CVE-2021-25266An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, a...3.9
- CVE-2012-6140pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictio...1.9
Product grouping is registry-driven, with AI assist and human review. How it works