Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Microfocus

First CVE: Jun 2, 2001Active for: 25 yearsTotal CVEs: 274
53.4
VTI Score
TOP TARGET

Microfocus maintains a broadly represented portfolio spanning identity and access management, IT service management, and directory infrastructure products that are widely deployed across enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure concentrates in products such as iManager, Access Manager, eDirectory, and Service Manager and recurs through weakness classes including input-validation and neutralization failures (cross-site scripting, XML external entity injection), cross-site request forgery, and sensitive information exposure that are characteristic of web-facing authentication and administrative interfaces. Defenders should treat Microfocus advisories affecting identity and access control systems as high-priority given their direct bearing on account compromise and lateral movement risk. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
274
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Microfocus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2001
25 years ago
Most Recent CVE
Jun 24, 2026
30 days ago

Products(97 total)

Top CVEs

Signals from CVEs in this vendor scope (274 CVEs).

274 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-22502CRITICAL
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execu
Feb 8, 20219.898YESYES
CVE-2019-5736HIGH
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
CVE-2018-12464CRITICAL
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbit
Jun 29, 20189.887NOYES
CVE-2020-11854CRITICAL
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products pr
Oct 27, 20209.885NOYES
CVE-2020-11853HIGH
Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, version
Oct 22, 20208.884NOYES
CVE-2018-12465HIGH
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user
Jun 29, 20187.283NOYES
CVE-2012-0432HIGH
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.
Dec 25, 201210.081NOYES
CVE-2012-5932HIGH
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote attackers to execute
Dec 24, 201210.081NOYES
CVE-2021-22506HIGH
Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0. The vulnerability could cause inf
Mar 26, 20217.575YESNO
CVE-2016-1606CRITICAL
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attackers to execute arbitrary code via (1) the NetworkName propert
Jul 3, 20169.868NOYES
View all 274 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products274 CVEs
44%
35%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (6.2%)
Network227 (82.8%)
Unknown22 (8.0%)
Physical0 (0.0%)
Adjacent Network8 (2.9%)
Attack Complexity
Low248 (90.5%)
High4 (1.5%)
Unknown22 (8.0%)
User Interaction
None167 (60.9%)
Unknown22 (8.0%)
Required85 (31.0%)
Privileges Required
Low82 (29.9%)
High15 (5.5%)
None155 (56.6%)
Unknown22 (8.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (274 CVEs).

CISA KEV
2 CVEs
0.7% of CVEs· 99th percentile
Metasploit
12 CVEs
4.4% of CVEs· 98th percentile
Nuclei
3 CVEs
1.1% of CVEs· 95th percentile
ExploitDB
20 CVEs
7.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Microfocus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Microfocus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Microfocus's Products

View all 5 CNAs →

Top CWEs