Altium
First CVE: Jan 15, 2026Active for: 1 year
20
CVEs Published
More CVEs Published than 39% of tracked CNAs
20.0
Avg CVEs / Year
More Avg CVEs / Year than 68% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Altium as a CNA, 55.0% affect products that Altium develops as a vendor.
55.0%
45.0%
Self-reported: 11Third-party: 9
Of all the CVEs published that affect products developed by Altium, 100.0% are self-published by Altium as a CNA.
100.0%
Self-published: 11Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by Altium over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 15, 2026
6 months ago
Most Recent CVE
Jul 1, 2026
24 days ago
Top CVEs
All CVEs published by Altium as a CNA, regardless of affected vendor or product.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14439CRITICAL A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation | Jul 1, 2026 | 9.4 | 41 | NO | NO |
CVE-2026-11429CRITICAL Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to con | Jun 5, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-11420CRITICAL Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any w | Jun 5, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-11423CRITICAL A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file down | Jun 5, 2026 | 9.4 | 38 | NO | NO |
CVE-2026-9152CRITICAL A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session toke | May 21, 2026 | 10.0 | 38 | NO | NO |
CVE-2026-11419HIGH A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload | Jun 5, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-11414CRITICAL A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauth | Jun 5, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-9102CRITICAL A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated | May 20, 2026 | 9.4 | 36 | NO | NO |
CVE-2026-9129CRITICAL A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments tha | May 20, 2026 | 9.4 | 35 | NO | NO |
CVE-2026-11424HIGH A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a reque | Jun 5, 2026 | 8.3 | 34 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA20 CVEs
30%
20%
50%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None12 (60.0%)
Unknown0 (0.0%)
Required8 (40.0%)
Privileges Required
Low14 (70.0%)
High0 (0.0%)
None6 (30.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Altium as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Altium as a CNA — matched by CVE ID, not by organization name.