Funambol develops mobile device management and data synchronization software, with its vulnerability profile centered on the Zefiro product line. The observed weakness class reflects path-traversal conditions in file-handling and directory-access logic, typical of synchronization platforms that mediate access to user data stores. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Funambol over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30286CRITICAL An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading | Mar 31, 2026 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Funambol.
Media articles that mention a CVE ID that affects a product developed by Funambol — matched by CVE ID, not by vendor name.