Automation Anywhere develops robotic process automation (RPA) software centered on its Automation 360 platform, which orchestrates business process workflows across enterprise environments. The observed vulnerability patterns center on data-handling and credential-management issues, including CSV formula injection and hard-coded credentials, reflecting the sensitive data access inherent to automation platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Automationanywhere over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6922MEDIUM Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Contro | Jul 26, 2024 | 6.9 | 48 | NO | YES |
CVE-2022-29856HIGH A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages. | Apr 29, 2022 | 7.5 | 24 | NO | NO |
CVE-2024-41226HIGH A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disput | Aug 6, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Automationanywhere.
Media articles that mention a CVE ID that affects a product developed by Automationanywhere — matched by CVE ID, not by vendor name.