Arc
25 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Arc, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Arc CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 7 |
| 2026-09 | 2 |
Severity
How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High9
- Medium6
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Arc.
- CVE-2026-94181Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element7.4
- CVE-2026-33389Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.07.5
- CVE-2026-55678Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset—
- CVE-2026-48106Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer—
- CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive—
- CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks—
- CVE-2026-48050Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS—
- CVE-2026-33922Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.06.0
- CVE-2026-33921Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.05.2
- CVE-2025-40896Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.06.5
- CVE-2024-52928Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.9.6
- CVE-2024-45489Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to ...9.8
- CVE-2023-5938Path traversal via 'zip slip' in Arc before v1.6.08.0
- CVE-2023-5937Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.03.8
- CVE-2023-5936Unsafe temporary data privileges on Unix systems in Arc before v1.6.07.8
Product grouping is registry-driven, with AI assist and human review. How it works