Mulesoft develops a focused integration platform centered on its Mule runtime, API gateway, and enterprise management tooling, deployed widely in enterprise middleware and API orchestration layers despite a narrow product footprint. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, particularly around deserialization flaws, path traversal, and XML entity injection that are characteristic of complex integration and data-transformation middleware. Defenders should prioritize patching this vendor's runtime and gateway components and restrict exposure of management consoles; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mulesoft over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13116CRITICAL The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collectio | Oct 16, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-15631CRITICAL Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code. | Dec 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-10991CRITICAL Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java | Mar 27, 2020 | 9.8 | 29 | NO | NO |
CVE-2014-9000MEDIUM Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges | Nov 20, 2014 | 6.5 | 29 | NO | YES |
CVE-2019-15630HIGH Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 a | Aug 30, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-6937HIGH A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource | May 29, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mulesoft.
Media articles that mention a CVE ID that affects a product developed by Mulesoft — matched by CVE ID, not by vendor name.