Milvus is a vector database platform designed for machine-learning and AI-search applications, with vulnerability disclosures concentrating in its core product around authentication and cryptographic implementation. The recurring weakness classes—missing authentication for critical functions, use of weak or broken cryptographic algorithms, and weak hashing—reflect typical challenges in securing data-access layers and credential handling in database systems. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Milvus over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26190CRITICAL Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication byp | Feb 13, 2026 | 9.8 | 58 | NO | YES |
CVE-2026-10814HIGH A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component | Jun 4, 2026 | 7.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Milvus.
Media articles that mention a CVE ID that affects a product developed by Milvus — matched by CVE ID, not by vendor name.