Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

BlackBerry

First CVE: Aug 12, 2002Active for: 24 yearsTotal CVEs: 88
53.1
VTI Score
TOP TARGET

BlackBerry maintains a focused but security-critical portfolio centered on the QNX real-time operating system, enterprise mobility management, and endpoint security platforms that span embedded systems, servers, and managed device fleets. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the high-value nature of endpoint management and embedded operating-system targets. The exposure recurs across products including QNX, the Unified Endpoint Manager, and enterprise server infrastructure through weakness classes spanning cross-site scripting, input validation failures, memory-safety issues, and sensitive-information disclosure—patterns consistent with both web-facing administrative interfaces and low-level system software. QNX in particular represents a durable legacy presence in automotive, industrial control, and embedded environments where patching cycles are lengthy and exposure windows extended. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
88
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
2.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by BlackBerry over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2002
23 years ago
Most Recent CVE
Nov 19, 2025
247 days ago

Self-Reporting Analysis

Of all the CVEs published by BlackBerry as a CNA, 82.3% affect products that BlackBerry develops as a vendor.

82.3%
17.7%
Self-reported: 51 (82.3%)
Third-party: 11 (17.7%)

Of all the CVEs published that affect products developed by BlackBerry, 58.0% are self-published by BlackBerry as a CNA.

58.0%
42.0%
Self-published: 51 (58.0%)
Other CNAs: 37 (42.0%)

Products(39 total)

Top CVEs

Signals from CVEs in this vendor scope (88 CVEs).

88 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-1938CRITICAL
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
CVE-2020-11652MEDIUM
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize pa
Apr 30, 20206.596YESYES
CVE-2014-2533HIGH
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.
Mar 18, 20147.242NOYES
CVE-2016-1914HIGH
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers
Apr 13, 20178.839NOYES
CVE-2008-3024HIGH
Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.
Jul 7, 20089.338NOYES
CVE-2021-22156CRITICAL
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1
Aug 17, 20219.832NONO
CVE-2025-2474CRITICAL
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in th
Jun 10, 20259.830NONO
CVE-2021-32024CRITICAL
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the a
Dec 13, 20219.830NONO
CVE-2017-9367CRITICAL
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary
Oct 16, 20179.830NONO
CVE-2025-3938CRITICAL
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This
May 22, 20259.829NONO
View all 88 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products88 CVEs
48%
38%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local12 (13.6%)
Network57 (64.8%)
Unknown18 (20.5%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low63 (71.6%)
High7 (8.0%)
Unknown18 (20.5%)
User Interaction
None52 (59.1%)
Unknown18 (20.5%)
Required18 (20.5%)
Privileges Required
Low18 (20.5%)
High5 (5.7%)
None47 (53.4%)
Unknown18 (20.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (88 CVEs).

CISA KEV
2 CVEs
2.3% of CVEs· 99th percentile
Metasploit
3 CVEs
3.4% of CVEs· 98th percentile
Nuclei
1 CVE
1.1% of CVEs· 95th percentile
ExploitDB
8 CVEs
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by BlackBerry.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by BlackBerry — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For BlackBerry's Products

View all 5 CNAs →

Top CWEs