Opswat develops a focused suite of endpoint security and file-validation products, including MetaDefender and MetaDefender Kiosk, that operate in security-critical positions such as web gateways, USB inspection, and threat detection pipelines. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, stemming from recurring weakness classes including improper privilege management, classic buffer overflows, command injection, and cross-site scripting that arise across its threat-scanning and validation components. Defenders should treat this vendor's advisories as high-priority given the sensitive data-handling role of its products; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opswat over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32272CRITICAL OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege e | Jun 9, 2022 | 9.8 | 46 | NO | YES |
CVE-2023-36659CRITICAL An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of commun | Sep 15, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-36657CRITICAL An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation. | Sep 15, 2023 | 9.8 | 28 | NO | NO |
CVE-2018-16275HIGH OPSWAT MetaDefender before v4.11.2 allows CSV injection. | Aug 31, 2018 | 7.8 | 25 | NO | NO |
CVE-2024-57695HIGH An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer f | Nov 11, 2025 | 7.7 | 24 | NO | NO |
CVE-2023-36658HIGH An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally. | Sep 15, 2023 | 7.8 | 23 | NO | NO |
CVE-2022-40778MEDIUM A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to execute arbitrary JavaScript or HTML because of the blocked p | Sep 19, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-32273MEDIUM As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server | Jun 8, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opswat.
Media articles that mention a CVE ID that affects a product developed by Opswat — matched by CVE ID, not by vendor name.