Hyland develops a focused portfolio of enterprise content-management and document-processing platforms, primarily OnBase and Alfresco-based products, that handle sensitive business records and workflows across large organizations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and span a range of weakness classes including deserialization flaws, path traversal, cross-site scripting, and memory-safety issues in document filters and transformation services. The exposure reflects the parsing and privilege demands inherent to systems that ingest untrusted documents and execute transformations on behalf of users, creating a meaningful surface for both code-execution and data-escape vectors. Defenders should prioritize this vendor's advisories given the criticality classification tendency and the sensitive data typically handled by these platforms; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hyland over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58126CRITICAL PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NE | Jul 1, 2026 | 9.8 | 43 | NO | NO |
CVE-2023-49964HIGH An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Sid | Dec 11, 2023 | 8.8 | 42 | NO | NO |
CVE-2026-58127CRITICAL PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any aut | Jul 1, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-26339CRITICAL Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document | Feb 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-26338CRITICAL Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality. | Feb 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2018-6292CRITICAL Remote Code Execution in Saperion Web Client version 7.5.2 83166. | Feb 13, 2018 | 9.8 | 32 | NO | NO |
CVE-2025-34153CRITICAL Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting | Aug 13, 2025 | 10.0 | 31 | NO | NO |
CVE-2020-25259CRITICAL An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses XML deserializat | Sep 11, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-25254CRITICAL An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, | Sep 11, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-25260CRITICAL An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attacke | Sep 11, 2020 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hyland.
Media articles that mention a CVE ID that affects a product developed by Hyland — matched by CVE ID, not by vendor name.