SoftIron
First CVE: Dec 5, 2023Active for: 3 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
1.5
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
4.4
Avg CVSS Score
Higher Avg CVSS Score than 2% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by SoftIron as a CNA, 100.0% affect products that SoftIron develops as a vendor.
100.0%
Self-reported: 6Third-party: 0
Of all the CVEs published that affect products developed by SoftIron, 100.0% are self-published by SoftIron as a CNA.
100.0%
Self-published: 6Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by SoftIron over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2023
2 years ago
Most Recent CVE
Feb 20, 2026
154 days ago
Top CVEs
All CVEs published by SoftIron as a CNA, regardless of affected vendor or product.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1842MEDIUM HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a re | Feb 20, 2026 | 6.2 | 21 | NO | NO |
CVE-2023-45084MEDIUM An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all | Dec 5, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-13058MEDIUM An issue exists in SoftIron HyperCloud
where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backe | Dec 30, 2024 | 4.8 | 16 | NO | NO |
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escal | Sep 18, 2025 | 1.8 | 15 | NO | NO |
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process. In this instance, workloads may be sch | Dec 5, 2023 | 3.3 | 14 | NO | NO |
CVE-2023-45083MEDIUM An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane.
An authenticated admin-le | Dec 5, 2023 | 4.4 | 14 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA6 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local2 (33.3%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical1 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (66.7%)
High1 (16.7%)
None1 (16.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by SoftIron as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SoftIron as a CNA — matched by CVE ID, not by organization name.