CVE Tools

Neuvector

14 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Neuvector, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Neuvector CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Neuvector CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-093
2025-103
2025-110
2025-120
2026-011
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-081
2026-093

Severity

How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical323%
  • High431%
  • Medium538%
  • Low18%

Latest CVEs

The 14 most recently published vulnerabilities affecting Neuvector.

  1. CVE-2026-78426Logout bypass via alternate JWT spelling3.7
  2. CVE-2026-78428Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently8.0
  3. CVE-2025-46808Sensitive information is leaked into NeuVector’s manager container logs6.8
  4. CVE-2026-25703Potential information leakage from manager /network/graph API in NeuVector7.3
  5. CVE-2025-66001NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)8.8
  6. CVE-2025-54471NeuVector is shipping cryptographic material into its binary6.5
  7. CVE-2025-54469NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow9.9
  8. CVE-2025-54470NeuVector telemetry sender is vulnerable to MITM and DoS8.6
  9. CVE-2025-8077NeuVector admin account has insecure default password9.8
  10. CVE-2025-54467NeuVector process with sensitive arguments lead to leakage5.3
  11. CVE-2025-53884NeuVector has an insecure password storage vulnerable to rainbow attack5.3
  12. CVE-2023-32188JWT token compromise can allow malicious actions including Remote Code Execution (RCE)—
  13. CVE-2023-22644JWT token compromise can allow malicious actions including Remote Code Execution (RCE)5.5
  14. CVE-2019-19747NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any ...9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store