Switzerland National Cyber Security Centre (NCSC)
First CVE: Nov 16, 2021Active for: 5 years
164
CVEs Published
More CVEs Published than 77% of tracked CNAs
27.3
Avg CVEs / Year
More Avg CVEs / Year than 75% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Switzerland National Cyber Security Centre (NCSC) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2021
4 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by Switzerland National Cyber Security Centre (NCSC) as a CNA, regardless of affected vendor or product.
164 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44127HIGH SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows | May 8, 2026 | 8.8 | 41 | NO | NO |
CVE-2026-8152CRITICAL Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.
When Unblu Spark is deployed with com.unblu.identifier | Jul 22, 2026 | 9.3 | 40 | NO | NO |
CVE-2026-8670CRITICAL Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay).
This issue affects Avantra: before | May 22, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-14551HIGH The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-8326CRITICAL Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The | May 29, 2026 | 10.0 | 38 | NO | NO |
CVE-2026-6213CRITICAL A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server sid | May 8, 2026 | 10.0 | 37 | NO | NO |
CVE-2026-7864MEDIUM SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain | May 8, 2026 | 6.9 | 36 | NO | NO |
CVE-2026-44128CRITICAL SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a pa | May 8, 2026 | 9.3 | 35 | NO | NO |
CVE-2026-29139CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. | Apr 2, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-13006HIGH ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitr | Jun 24, 2026 | 7.0 | 34 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA164 CVEs
38%
36%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (10.4%)
Network135 (82.3%)
Unknown0 (0.0%)
Physical4 (2.4%)
Adjacent Network2 (1.2%)
Attack Complexity
Low149 (90.9%)
High15 (9.1%)
Unknown0 (0.0%)
User Interaction
None124 (75.6%)
Unknown0 (0.0%)
Required25 (15.2%)
Privileges Required
Low41 (25.0%)
High13 (7.9%)
None110 (67.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (164 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.6% of CVEs· 77th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Switzerland National Cyber Security Centre (NCSC) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Switzerland National Cyber Security Centre (NCSC) as a CNA — matched by CVE ID, not by organization name.