Environmental Systems Research Institute (Esri) maintains a portfolio of geographic information systems and mapping applications that includes Portal for ArcGIS, ArcGIS Server, ArcGIS Pro, and ArcGIS Enterprise, products deeply embedded in critical infrastructure, government, and enterprise spatial-data workflows. The vendor's vulnerability profile clusters around web-facing input-handling and server-side processing weaknesses, with recurring issues in cross-site scripting, open redirects, path traversal, SQL injection, and server-side request forgery that reflect the complexity of web-based GIS services and their integration with external data sources. A meaningful share of the vendor's disclosures reach serious severity, though the modest exploit-availability tendency suggests that weaponization does not immediately follow disclosure. Because these products often serve as authoritative spatial-data sources and sit at architectural boundaries in mission-critical deployments, defenders should prioritize patching for this vendor and treat its advisories as applicable across both internet-facing services and trusted internal networks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Environmental Systems Research Institute, Inc. over time
Of all the CVEs published by Environmental Systems Research Institute, Inc. as a CNA, 98.1% affect products that Environmental Systems Research Institute, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Environmental Systems Research Institute, Inc., 89.3% are self-published by Environmental Systems Research Institute, Inc. as a CNA.
Signals from CVEs in this vendor scope (169 CVEs).
169 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1661HIGH ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitra | Jul 12, 2012 | 9.3 | 53 | NO | YES |
CVE-2007-1770HIGH Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, a | Mar 30, 2007 | 10.0 | 45 | NO | YES |
CVE-2026-9181CRITICAL Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending cr | Jul 6, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-13019CRITICAL Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated | Jul 7, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-9182CRITICAL Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Su | Jul 6, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-13020CRITICAL A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attack | Jul 7, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-33519CRITICAL An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to | Apr 21, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-33518CRITICAL An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that | Apr 21, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-57870CRITICAL A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attack | Oct 22, 2025 | 10.0 | 32 | NO | NO |
CVE-2022-38193CRITICAL There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentiall | Aug 16, 2022 | 9.6 | 31 | NO | NO |
Signals from CVEs in this vendor scope (169 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Environmental Systems Research Institute, Inc..
Media articles that mention a CVE ID that affects a product developed by Environmental Systems Research Institute, Inc. — matched by CVE ID, not by vendor name.