Jamf
First CVE: Jun 27, 2024Active for: 2 years
3
CVEs Published
More CVEs Published than 9% of tracked CNAs
1.5
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 11% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Jamf as a CNA, 0.0% affect products that Jamf develops as a vendor.
100.0%
Self-reported: 0Third-party: 3
Of all the CVEs published that affect products developed by Jamf, 0.0% are self-published by Jamf as a CNA.
100.0%
Self-published: 0Published by other CNAs: 10
Trends Over Time
The number and severity of CVEs published by Jamf over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2024
2 years ago
Most Recent CVE
Jan 21, 2026
184 days ago
Top CVEs
All CVEs published by Jamf as a CNA, regardless of affected vendor or product.
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1290MEDIUM Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Jamf Pro: from 11.20 through 11.24. | Jan 21, 2026 | 5.3 | 23 | NO | NO |
CVE-2024-4395HIGH The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation. | Jun 27, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-10183MEDIUM A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems. | Oct 22, 2024 | 5.2 | 17 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA3 CVEs
67%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (66.7%)
Network1 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Jamf as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Jamf as a CNA — matched by CVE ID, not by organization name.