Extreme Networks, Inc.
Self-Reporting Analysis
Of all the CVEs published by Extreme Networks, Inc. as a CNA, 62.5% affect products that Extreme Networks, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Extreme Networks, Inc., 16.7% are self-published by Extreme Networks, Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Extreme Networks, Inc. over time
Top CVEs
All CVEs published by Extreme Networks, Inc. as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8170HIGH The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privile | Jul 20, 2026 | 8.7 | 37 | NO | NO |
CVE-2026-8169HIGH ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random sou | Jul 20, 2026 | 8.7 | 36 | NO | NO |
CVE-2025-8679CRITICAL In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID | Oct 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-9831MEDIUM A race condition in the shared Extreme Platform
ONE IAM Gateway API-key authentication path could, under specific
high-concurrency traffic conditions, intermittently allow requests | May 29, 2026 | 6.3 | 29 | NO | NO |
CVE-2025-11192HIGH A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity | Oct 7, 2025 | 8.6 | 26 | NO | NO |
CVE-2025-6235MEDIUM In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling | Jul 21, 2025 | 6.1 | 18 | NO | NO |
CVE-2026-0689MEDIUM In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive | Mar 2, 2026 | 4.9 | 17 | NO | NO |
CVE-2025-6083MEDIUM In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the e | Jun 13, 2025 | 4.3 | 15 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Extreme Networks, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Extreme Networks, Inc. as a CNA — matched by CVE ID, not by organization name.