Citeum maintains OpenCTI, a threat intelligence and case-management platform widely used for security operations and intelligence workflows. The vendor's vulnerability footprint, while concentrated in a single product, skews toward serious outcomes with an elevated share reaching critical severity, reflecting the authentication and input-handling demands of a web-based platform with privileged access to sensitive intelligence data. The recurring weakness classes—improper access control, authorization bypass, and cross-site scripting—center on the attack surface presented by web-tier input handling and role-based access logic. Defenders deploying OpenCTI should prioritize updates for this vendor and restrict network exposure of the platform; current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Citeum over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27960CRITICAL OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability | May 5, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-35210HIGH OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability in OpenCTI allows an | Jul 8, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-35211MEDIUM OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator i | Jul 8, 2026 | 6.5 | 29 | NO | NO |
CVE-2025-61781CRITICAL OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" | Jan 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2025-24977CRITICAL OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying inf | May 5, 2025 | 9.1 | 29 | NO | NO |
CVE-2026-39980HIGH OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. U | Apr 9, 2026 | 7.2 | 27 | NO | NO |
CVE-2026-35212MEDIUM OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-me | Jun 2, 2026 | 6.1 | 26 | NO | NO |
CVE-2026-21886HIGH OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualDeletionDeleteMutation | Mar 17, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-21887HIGH OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-sup | Mar 12, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-44730HIGH OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a | May 26, 2026 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Citeum.
Media articles that mention a CVE ID that affects a product developed by Citeum — matched by CVE ID, not by vendor name.