Akamai's vulnerability profile, though narrow in product scope, centers on critical client-access and content-delivery software deployed across enterprise networks, where its disclosures skew toward serious outcomes. The recurring weakness classes—code injection, untrusted deserialization, certificate validation flaws, HTTP request smuggling, and authorization failures—span both client-side application interaction and protocol-handling layers, reflecting the vendor's role at the boundary between user endpoints and backend infrastructure. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Akamai over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1770HIGH CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL para | Jun 4, 2008 | 9.3 | 37 | NO | YES |
CVE-2025-49493MEDIUM Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. | Jun 30, 2025 | 5.8 | 31 | NO | YES |
CVE-2019-18847CRITICAL Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1. | Aug 26, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-11011CRITICAL Akamai CloudTest before 58.30 allows remote code execution. | Jun 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2016-10157CRITICAL Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is mi | Jan 23, 2017 | 9.8 | 31 | NO | NO |
CVE-2025-24527HIGH An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands | Jan 29, 2025 | 8.0 | 23 | NO | NO |
CVE-2021-40683HIGH In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of executio | Oct 4, 2021 | 7.8 | 23 | NO | NO |
CVE-2025-66373MEDIUM Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an inval | Dec 4, 2025 | 4.8 | 22 | NO | NO |
CVE-2024-45164HIGH Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0. | Nov 4, 2024 | 7.1 | 20 | NO | NO |
CVE-2025-52491MEDIUM Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF. | Jun 30, 2025 | 5.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Akamai.
Media articles that mention a CVE ID that affects a product developed by Akamai — matched by CVE ID, not by vendor name.