Altium is a specialized electronics design software vendor whose vulnerability footprint, while modest in volume, represents a concentrated attack surface across on-premises enterprise servers and collaborative design platforms. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through web-application weakness classes including cross-site scripting, improper access control, improper certificate validation, and input-handling flaws that are characteristic of server and browser-based design tools. Defenders managing Altium deployments should prioritize patch application for server and authentication components; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altium over time
Of all the CVEs published by Altium as a CNA, 55.0% affect products that Altium develops as a vendor.
Of all the CVEs published that affect products developed by Altium, 100.0% are self-published by Altium as a CNA.
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11420CRITICAL Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any w | Jun 5, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-11419HIGH A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload | Jun 5, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-11414CRITICAL A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauth | Jun 5, 2026 | 9.8 | 37 | NO | NO |
CVE-2025-27378CRITICAL AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, c | Jan 22, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-27380HIGH HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser | Jan 22, 2026 | 7.6 | 28 | NO | NO |
CVE-2025-27377MEDIUM Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could ex | Jan 22, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-1011MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interfa | Jan 16, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-1009MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inje | Jan 15, 2026 | 5.4 | 22 | NO | NO |
CVE-2025-27379MEDIUM A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field o | Jan 22, 2026 | 4.6 | 21 | NO | NO |
CVE-2026-1010MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular aut | Jan 15, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altium.
Media articles that mention a CVE ID that affects a product developed by Altium — matched by CVE ID, not by vendor name.