Keystorage's vulnerability footprint centers on global facilities management software, where the durable signal reflects application-layer and credential-handling weaknesses including cross-site scripting, improper privilege management, hard-coded credentials, and memory-safety issues such as out-of-bounds writes. The observed pattern also includes the practice of embedding sensitive parameters in HTTP query strings, a structural design weakness that compounds exposure in web-facing facility control systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keystorage over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26722CRITICAL An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality. | Feb 20, 2026 | 9.4 | 29 | NO | NO |
CVE-2022-45766CRITICAL Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, conf | Feb 10, 2023 | 9.1 | 27 | NO | NO |
CVE-2026-26723HIGH Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function paramet | Feb 20, 2026 | 8.2 | 26 | NO | NO |
CVE-2026-26724HIGH Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the selectgroup and | Feb 20, 2026 | 7.6 | 24 | NO | NO |
CVE-2026-26721HIGH An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter. | Feb 20, 2026 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keystorage.
Media articles that mention a CVE ID that affects a product developed by Keystorage — matched by CVE ID, not by vendor name.