Nozominetworks develops network visibility and operational-technology security products, including the Guardian and Central Management Control platforms, that are deployed across critical-infrastructure and industrial environments to monitor and defend networked systems. The vendor's vulnerability footprint, though narrow in product scope, ranks among more prominent vendors in the landscape due to the security-critical role these appliances play in monitoring and controlling operational networks. Vulnerabilities affecting the vendor recur consistently through application-layer input-handling weakness classes: cross-site scripting, SQL injection, path traversal, and improper input validation are the durable signals across its product line, reflecting the web-interface and API-driven architecture of network management appliances. Defenders should treat this vendor's advisories as high-priority for any deployed Guardian or Central Management Control instance, since these products sit between operators and their critical infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nozominetworks over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33390HIGH An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited | Jul 9, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-31984HIGH A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audi | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-31982HIGH An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated | Jul 9, 2026 | 7.1 | 32 | NO | NO |
CVE-2025-40892HIGH A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileg | Dec 18, 2025 | 8.9 | 28 | NO | NO |
CVE-2025-40886HIGH A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute | Oct 7, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-4259HIGH Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary S | May 4, 2023 | 8.8 | 28 | NO | NO |
CVE-2026-31983MEDIUM A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpo | Jul 9, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-31981MEDIUM A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated | Jul 9, 2026 | 4.8 | 26 | NO | NO |
CVE-2025-3719HIGH An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authe | Oct 7, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-40898HIGH A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited priv | Dec 18, 2025 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nozominetworks.
Media articles that mention a CVE ID that affects a product developed by Nozominetworks — matched by CVE ID, not by vendor name.