Natroteam's vulnerability profile centers on Natro Macro, a file-processing product where disclosures cluster around authentication, code-injection, and file-handling weaknesses. The observed weakness classes—including improper authentication, code injection, path traversal, and unrestricted file uploads—reflect the parser and script-execution demands of macro-enabled document processing; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Natroteam over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28801HIGH Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code contained inside of a pattern or path file is executed by the ma | Mar 6, 2026 | 7.8 | 25 | NO | NO |
CVE-2026-28800HIGH Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-private channel gives acce | Mar 6, 2026 | 8.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Natroteam.
Media articles that mention a CVE ID that affects a product developed by Natroteam — matched by CVE ID, not by vendor name.