Mullvad offers a privacy-focused VPN client with a modest disclosed vulnerability footprint centered on its core VPN application, where exposure recurs across privilege-management and access-control weakness classes alongside data-authentication and search-path issues. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mullvad over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32323HIGH Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upg | May 19, 2026 | 7.8 | 30 | NO | NO |
CVE-2023-50446HIGH An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to escalate privileges to SYSTEM. | Dec 10, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mullvad.
Media articles that mention a CVE ID that affects a product developed by Mullvad — matched by CVE ID, not by vendor name.