Airbus
First CVE: Apr 12, 2019Active for: 7 years
24
CVEs Published
More CVEs Published than 45% of tracked CNAs
4.8
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Airbus as a CNA, 4.2% affect products that Airbus develops as a vendor.
95.8%
Self-reported: 1Third-party: 23
Of all the CVEs published that affect products developed by Airbus, 100.0% are self-published by Airbus as a CNA.
100.0%
Self-published: 1Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by Airbus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2019
7 years ago
Most Recent CVE
Jul 2, 2026
22 days ago
Top CVEs
All CVEs published by Airbus as a CNA, regardless of affected vendor or product.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-10539CRITICAL A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to | Jul 1, 2026 | 9.0 | 40 | NO | NO |
CVE-2026-10538HIGH Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Co | Jul 1, 2026 | 8.0 | 35 | NO | NO |
CVE-2019-10880CRITICAL Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vuln | Apr 12, 2019 | 9.8 | 35 | NO | NO |
CVE-2025-55108CRITICAL The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not | Nov 5, 2025 | 10.0 | 34 | NO | NO |
CVE-2025-55113CRITICAL If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlie | Sep 16, 2025 | 10.0 | 34 | NO | NO |
CVE-2026-10540MEDIUM The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained | Jul 1, 2026 | 5.6 | 28 | NO | NO |
CVE-2025-55118HIGH Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured.
The issue occurs in the following cases:
* Control-M/Agent 9.0.2 | Sep 16, 2025 | 8.9 | 28 | NO | NO |
CVE-2025-55109CRITICAL An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or de | Sep 16, 2025 | 9.0 | 28 | NO | NO |
CVE-2019-10881CRITICAL Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded pass | Apr 13, 2021 | 9.8 | 28 | NO | NO |
CVE-2025-55116HIGH A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent.
This vulnerability impacts the out-o | Sep 16, 2025 | 8.8 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA24 CVEs
38%
38%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (41.7%)
Network12 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (8.3%)
Attack Complexity
Low18 (75.0%)
High6 (25.0%)
Unknown0 (0.0%)
User Interaction
None22 (91.7%)
Unknown0 (0.0%)
Required2 (8.3%)
Privileges Required
Low9 (37.5%)
High3 (12.5%)
None12 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Airbus as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Airbus as a CNA — matched by CVE ID, not by organization name.