Pangolin's vulnerability profile centers on a focused product line with a modest presence in the landscape, where observed weaknesses cluster around authentication and secure initialization. The recurring exposure points involve improper authentication mechanisms and insecure default configurations, typical of products where access control and baseline hardening are critical security boundaries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pangolin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56333CRITICAL An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component | Dec 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-56332CRITICAL Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default Configuration | Dec 30, 2025 | 9.1 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pangolin.
Media articles that mention a CVE ID that affects a product developed by Pangolin — matched by CVE ID, not by vendor name.