Calero maintains a narrowly scoped software portfolio centered on the VeraSmart product, which addresses IT asset management and vendor optimization. The recurring vulnerability signal centers on trust and authentication boundaries—untrusted deserialization, missing authentication for critical functions, hard-coded credentials, and hard-coded cryptographic keys—reflecting common challenges in systems that handle privileged configuration and asset data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Calero over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26335CRITICAL Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\Ve | Feb 13, 2026 | 9.8 | 42 | NO | YES |
CVE-2026-26333CRITICAL Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer | Feb 13, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-26334HIGH Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). These keys are used to encrypt t | Feb 13, 2026 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Calero.
Media articles that mention a CVE ID that affects a product developed by Calero — matched by CVE ID, not by vendor name.