Adguard's vulnerability footprint spans a modestly represented set of content-filtering and DNS-protection products, including AdGuard Home, AdGuard DNS, and browser extensions, which operate across client and network-layer deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while recurring weakness classes center on authentication, access control, and input validation issues characteristic of web-facing administrative interfaces and network services. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adguard over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32136CRITICAL AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending | Mar 11, 2026 | 9.8 | 34 | NO | NO |
CVE-2021-27935HIGH An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is store | Mar 3, 2021 | 7.5 | 26 | NO | NO |
CVE-2022-45770HIGH Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation. | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2026-24902HIGH TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF p | Jan 29, 2026 | 7.1 | 24 | NO | NO |
CVE-2023-41173HIGH AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets. | Aug 25, 2023 | 7.5 | 21 | NO | NO |
CVE-2022-32175MEDIUM In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an a | Oct 11, 2022 | 5.4 | 20 | NO | NO |
CVE-2026-24904MEDIUM TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_ | Jan 29, 2026 | 5.3 | 19 | NO | NO |
CVE-2025-51497MEDIUM An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went int | Jul 17, 2025 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adguard.
Media articles that mention a CVE ID that affects a product developed by Adguard — matched by CVE ID, not by vendor name.