Bishop Fox is a provider of offensive security tools and services, with vulnerability disclosures focused on Sliver, an open-source command-and-control framework designed as a modular alternative to Beacon. The recurring weakness classes affecting this platform—including missing authentication for critical functions, resource exhaustion, path traversal, excessive memory allocation, and NULL-pointer dereferences—reflect the inherent complexity of managing remote command execution and inter-process communication in adversary-emulation tooling. Current severity, exploitation activity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bishopfox over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34227HIGH Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immedi | Mar 31, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-25791HIGH Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates s | Feb 9, 2026 | 7.5 | 25 | NO | NO |
CVE-2023-34758HIGH Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses. | Aug 28, 2023 | 8.1 | 24 | NO | NO |
CVE-2026-32941MEDIUM Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remote OOM (Out-of-Memory) vulnerability in the Sliver C2 server | Mar 20, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-29781MEDIUM Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarsh | Mar 7, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-25760MEDIUM Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator r | Feb 6, 2026 | 6.5 | 20 | NO | NO |
CVE-2025-27090MEDIUM Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwardin | Feb 19, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bishopfox.
Media articles that mention a CVE ID that affects a product developed by Bishopfox — matched by CVE ID, not by vendor name.