GFI develops a focused suite of messaging, archival, and IT infrastructure management products, including Mail Essentials, Archiver, Helpdesk, and Kerio-branded connectivity and firewall appliances, that serve small to medium-sized business environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the internet-exposed and authentication-critical nature of messaging gateways and remote-access appliances. The exposure recurs across its product portfolio through weakness classes centered on web-application input handling—including cross-site scripting and code injection—alongside unsafe deserialization and missing authentication controls, patterns typical of business-productivity software with web and API interfaces. Defenders should prioritize patches for internet-reachable instances of these products and restrict administrative access; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gfi over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52875HIGH An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expira | Jan 31, 2025 | 8.8 | 56 | NO | YES |
CVE-2021-29281CRITICAL File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-20 | Jul 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-34069CRITICAL An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transp | Jul 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-2039CRITICAL GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of | Feb 20, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-2038CRITICAL GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of G | Feb 20, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-34071CRITICAL A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade featu | Jul 2, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-34070CRITICAL A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent s | Jul 2, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-35940HIGH The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected Archiv | Jun 10, 2025 | 8.1 | 28 | NO | NO |
CVE-2024-11948CRITICAL GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Aut | Dec 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-2037HIGH GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta | Feb 20, 2026 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gfi.
Media articles that mention a CVE ID that affects a product developed by Gfi — matched by CVE ID, not by vendor name.