Northern.Tech maintains a modest portfolio of infrastructure and device-management tools, including configuration-management, OS update, and user-administration products that operate in privileged or trust-boundary positions within enterprise environments. Its vulnerability profile centers on access-control and input-handling weaknesses—including improper default permissions, access-control flaws, cross-site scripting, cross-site request forgery, and certificate-validation issues—that recur across its product line and reflect the authentication and web-interface demands of management-tier software. Defenders should prioritize patch deployment for these products given their administrative access scope; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Northern.Tech over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29556CRITICAL The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execu | Apr 28, 2022 | 9.8 | 29 | NO | NO |
CVE-2026-24712HIGH Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. | May 14, 2026 | 7.3 | 27 | NO | NO |
CVE-2022-29555HIGH The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking. | Apr 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2026-24710MEDIUM Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. | May 14, 2026 | 6.1 | 23 | NO | NO |
CVE-2023-45684HIGH Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission | Nov 14, 2023 | 7.5 | 22 | NO | NO |
CVE-2021-35342HIGH The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the sys | Aug 27, 2021 | 7.5 | 22 | NO | NO |
CVE-2026-24711MEDIUM Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. | May 14, 2026 | 5.3 | 21 | NO | NO |
CVE-2023-26560MEDIUM Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover cr | Apr 26, 2023 | 6.5 | 21 | NO | NO |
CVE-2021-36756MEDIUM CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. | Oct 27, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-44215MEDIUM Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. | Mar 10, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Northern.Tech.
Media articles that mention a CVE ID that affects a product developed by Northern.Tech — matched by CVE ID, not by vendor name.