Malwarebytes develops security and system-maintenance software spanning endpoint protection, malware detection, and firewall control products that are widely deployed across consumer and enterprise environments. The vulnerability exposure recurs across its core products, including the Malwarebytes antimalware platform and complementary tools such as ADWCleaner and Windows Firewall Control, and clusters around input-validation and file-access weaknesses that reflect the complexity of threat detection and system-level integration work. A moderate share of the vendor's disclosures acquire public exploit code, presenting a tangible remediation priority for deployments of affected versions. Defenders should monitor this vendor's release cycles and prioritize patching for internet-accessible or high-value endpoint instances; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Malwarebytes over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4936HIGH The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle at | Dec 16, 2014 | 9.3 | 59 | NO | YES |
CVE-2022-50971HIGH Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into t | Jun 19, 2026 | 7.8 | 33 | NO | NO |
CVE-2019-6739HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit thi | Jun 3, 2019 | 8.8 | 33 | NO | NO |
CVE-2022-25150HIGH In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges. | Feb 14, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-11507HIGH An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded. | Apr 6, 2020 | 7.8 | 25 | NO | NO |
CVE-2024-25089CRITICAL Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes. | Feb 4, 2024 | 9.8 | 24 | NO | NO |
CVE-2023-28892HIGH Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-c | Mar 29, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-26088HIGH In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalati | Mar 23, 2023 | 7.8 | 24 | NO | NO |
CVE-2020-25533HIGH An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged s | Jan 15, 2021 | 7.0 | 24 | NO | NO |
CVE-2019-19929HIGH An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by | Dec 23, 2019 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Malwarebytes.
Media articles that mention a CVE ID that affects a product developed by Malwarebytes — matched by CVE ID, not by vendor name.