Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jamf

First CVE: Sep 28, 2012Active for: 14 yearsTotal CVEs: 10
44.1
VTI Score
High

Jamf is a specialized mobile device management and endpoint security vendor with a focused but critical product portfolio—including Jamf Pro, Casper Suite, Private Access, and Self Service—that sits in the management and access-control path for enterprise Apple ecosystems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the elevated value of flaws in trust and authentication boundaries within management platforms. The recurring weakness classes, including server-side request forgery, cross-site request forgery, deserialization of untrusted data, and improper authentication, are characteristic of the integration and privilege-escalation risks inherent to centralized device-management and identity-proxy roles. Defenders should prioritize Jamf advisories and treat internet-reachable instances as high-risk; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jamf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 28, 2012
13 years ago
Most Recent CVE
Dec 25, 2023
942 days ago

Self-Reporting Analysis

Of all the CVEs published by Jamf as a CNA, 0.0% affect products that Jamf develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 3 (100.0%)

Of all the CVEs published that affect products developed by Jamf, 0.0% are self-published by Jamf as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 10 (100.0%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-4051MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers t
Sep 28, 20126.833NOYES
CVE-2021-39303CRITICAL
The server in Jamf Pro before 10.32.0 has an SSRF vulnerability, aka PI-006352. NOTE: Jamf Nation will also publish an article about this vulnerability.
Nov 12, 20219.831NONO
CVE-2021-40809HIGH
An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows
Dec 1, 20218.828NONO
CVE-2019-17076CRITICAL
An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code
Jan 8, 20209.828NONO
CVE-2023-31224CRITICAL
There is broken access control during authentication in Jamf Pro Server before 10.46.1.
Dec 25, 20239.826NONO
CVE-2022-29564HIGH
Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801.
Jun 7, 20227.524NONO
CVE-2021-35037MEDIUM
Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that
Jul 12, 20216.122NONO
CVE-2018-10465HIGH
Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jamf Pro had full access to endpoints in the Universal API (UAP
Jan 7, 20208.822NONO
CVE-2021-30125MEDIUM
Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.
Apr 2, 20216.121NONO
CVE-2019-9146HIGH
Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to insert "/Applications/Utilities/Termina
Feb 25, 20197.519NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
40%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (80.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network1 (10.0%)
Attack Complexity
Low8 (80.0%)
High1 (10.0%)
Unknown1 (10.0%)
User Interaction
None7 (70.0%)
Unknown1 (10.0%)
Required2 (20.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None7 (70.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jamf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jamf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jamf's Products

View all 1 CNAs →

Top CWEs