Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Alibaba, Inc.

First CVE: Feb 7, 2007Active for: 19 yearsTotal CVEs: 13
51.8
VTI Score
TOP TARGET

Alibaba's vulnerability profile centers on a focused set of widely deployed open-source and enterprise middleware products—particularly Nacos, Fastjson, Druid, and Alipay ActiveX Control—that serve critical roles in distributed systems, data access layers, and financial applications. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the recurring weakness classes, including deserialization of untrusted data, authentication bypass, path traversal, and improper input validation, reflect the complexity of large-scale integration platforms and the high-value targets they represent. Defenders should prioritize updates for these infrastructure and middleware components, particularly in internet-connected deployments; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Alibaba, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2007
19 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Self-Reporting Analysis

Of all the CVEs published by Alibaba, Inc. as a CNA, 50.0% affect products that Alibaba, Inc. develops as a vendor.

50.0%
50.0%
Self-reported: 2 (50.0%)
Third-party: 2 (50.0%)

Of all the CVEs published that affect products developed by Alibaba, Inc., 15.4% are self-published by Alibaba, Inc. as a CNA.

15.4%
84.6%
Self-published: 2 (15.4%)
Other CNAs: 11 (84.6%)

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-29441CRITICAL
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.c
Apr 27, 20219.881NOYES
CVE-2021-29442HIGH
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform ma
Apr 27, 20217.569NOYES
CVE-2017-18349CRITICAL
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, a
Oct 23, 20189.864NOYES
CVE-2021-43116HIGH
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package
Jul 5, 20228.842NOYES
CVE-2026-16723CRITICAL
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType e
Jul 23, 20269.039NONO
CVE-2022-25845CRITICAL
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under
Jun 10, 20229.839NONO
CVE-2025-70974CRITICAL
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain pu
Jan 9, 202610.037NONO
CVE-2007-0827MEDIUM
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid i
Feb 7, 20076.828NOYES
CVE-2021-33800HIGH
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
Nov 3, 20217.524NONO
CVE-2021-44667MEDIUM
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
Mar 11, 20226.121NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
31%
31%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown2 (15.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High1 (7.7%)
Unknown2 (15.4%)
User Interaction
None10 (76.9%)
Unknown2 (15.4%)
Required1 (7.7%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None10 (76.9%)
Unknown2 (15.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
23.1% of CVEs· 97th percentile
ExploitDB
2 CVEs
15.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Alibaba, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Alibaba, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Alibaba, Inc.'s Products

View all 5 CNAs →

Top CWEs