Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Akamai

First CVE: Jun 4, 2008Active for: 18 yearsTotal CVEs: 10
51.6
VTI Score
TOP TARGET

Akamai's vulnerability profile, though narrow in product scope, centers on critical client-access and content-delivery software deployed across enterprise networks, where its disclosures skew toward serious outcomes. The recurring weakness classes—code injection, untrusted deserialization, certificate validation flaws, HTTP request smuggling, and authorization failures—span both client-side application interaction and protocol-handling layers, reflecting the vendor's role at the boundary between user endpoints and backend infrastructure. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Akamai over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2008
18 years ago
Most Recent CVE
Dec 4, 2025
234 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-1770HIGH
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL para
Jun 4, 20089.337NOYES
CVE-2025-49493MEDIUM
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
Jun 30, 20255.831NOYES
CVE-2019-18847CRITICAL
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
Aug 26, 20209.831NONO
CVE-2019-11011CRITICAL
Akamai CloudTest before 58.30 allows remote code execution.
Jun 21, 20199.831NONO
CVE-2016-10157CRITICAL
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is mi
Jan 23, 20179.831NONO
CVE-2025-24527HIGH
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands
Jan 29, 20258.023NONO
CVE-2021-40683HIGH
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of executio
Oct 4, 20217.823NONO
CVE-2025-66373MEDIUM
Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an inval
Dec 4, 20254.822NONO
CVE-2024-45164HIGH
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.
Nov 4, 20247.120NONO
CVE-2025-52491MEDIUM
Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.
Jun 30, 20255.818NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
40%
30%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network8 (80.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (70.0%)
High2 (20.0%)
Unknown1 (10.0%)
User Interaction
None8 (80.0%)
Unknown1 (10.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None7 (70.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Akamai.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Akamai — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Akamai's Products

View all 1 CNAs →

Top CWEs