Falco is a container and host runtime-security monitoring tool that operates deep within Linux kernel and containerized environments, presenting a narrow but strategically positioned product surface. The vulnerability disclosures associated with this vendor cluster around privilege-management and memory-safety weakness classes, reflecting the kernel-adjacent instrumentation and native-code footprint characteristic of runtime monitoring agents. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Falco over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33505HIGH A local malicious user can circumvent the Falco detection engine through 0.28.1 by running a program that alters arguments of system calls being executed. Issue is fixed in Falco v | Jul 15, 2021 | 7.8 | 25 | NO | NO |
CVE-2019-8339MEDIUM An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine. | May 17, 2019 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Falco.
Media articles that mention a CVE ID that affects a product developed by Falco — matched by CVE ID, not by vendor name.