Open-Xchange
First CVE: Apr 4, 2023Active for: 3 years
146
CVEs Published
More CVEs Published than 75% of tracked CNAs
36.5
Avg CVEs / Year
More Avg CVEs / Year than 80% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Open-Xchange as a CNA, 0.0% affect products that Open-Xchange develops as a vendor.
100.0%
Self-reported: 0Third-party: 146
Trends Over Time
The number and severity of CVEs published by Open-Xchange over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Open-Xchange as a CNA, regardless of affected vendor or product.
146 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33612HIGH A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning. | Jun 25, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-27851CRITICAL When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can | May 12, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-42000HIGH Insufficient Validation of Names During AXFR | May 21, 2026 | 8.6 | 34 | NO | NO |
CVE-2026-42002HIGH Concurrency and locking defects in GSS-TSIG | May 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-42001HIGH Insufficient Validation of Autoprimary SOA Queries | May 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-24028HIGH An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of- | Mar 31, 2026 | 8.2 | 32 | NO | NO |
CVE-2026-52688HIGH RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation | Jul 23, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-42006HIGH An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still | May 12, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-33608CRITICAL An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, lea | Apr 22, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-27853HIGH An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in cust | Mar 31, 2026 | 7.5 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA146 CVEs
56%
34%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (4.1%)
Network132 (90.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (5.5%)
Attack Complexity
Low123 (84.2%)
High23 (15.8%)
Unknown0 (0.0%)
User Interaction
None116 (79.5%)
Unknown0 (0.0%)
Required30 (20.5%)
Privileges Required
Low44 (30.1%)
High4 (2.7%)
None98 (67.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (146 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Open-Xchange as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Open-Xchange as a CNA — matched by CVE ID, not by organization name.