Jamf is a specialized mobile device management and endpoint security vendor with a focused but critical product portfolio—including Jamf Pro, Casper Suite, Private Access, and Self Service—that sits in the management and access-control path for enterprise Apple ecosystems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the elevated value of flaws in trust and authentication boundaries within management platforms. The recurring weakness classes, including server-side request forgery, cross-site request forgery, deserialization of untrusted data, and improper authentication, are characteristic of the integration and privilege-escalation risks inherent to centralized device-management and identity-proxy roles. Defenders should prioritize Jamf advisories and treat internet-reachable instances as high-risk; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jamf over time
Of all the CVEs published by Jamf as a CNA, 0.0% affect products that Jamf develops as a vendor.
Of all the CVEs published that affect products developed by Jamf, 0.0% are self-published by Jamf as a CNA.
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4051MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers t | Sep 28, 2012 | 6.8 | 33 | NO | YES |
CVE-2021-39303CRITICAL The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability. | Nov 12, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-40809HIGH An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows | Dec 1, 2021 | 8.8 | 28 | NO | NO |
CVE-2019-17076CRITICAL An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code | Jan 8, 2020 | 9.8 | 28 | NO | NO |
CVE-2023-31224CRITICAL There is broken access control during authentication in Jamf Pro Server before 10.46.1. | Dec 25, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-29564HIGH Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801. | Jun 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-35037MEDIUM Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that | Jul 12, 2021 | 6.1 | 22 | NO | NO |
CVE-2018-10465HIGH Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jamf Pro had full access to endpoints in the Universal API (UAP | Jan 7, 2020 | 8.8 | 22 | NO | NO |
CVE-2021-30125MEDIUM Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376. | Apr 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-9146HIGH Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to insert "/Applications/Utilities/Termina | Feb 25, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jamf.
Media articles that mention a CVE ID that affects a product developed by Jamf — matched by CVE ID, not by vendor name.