Skyhighsecurity focuses on secure web gateway products designed to protect traffic and enforce content policies at the network edge. The vendor's vulnerability profile centers on authentication and sensitive-data handling weaknesses—including authentication bypass via spoofing, cleartext storage of credentials and sensitive information, and information-disclosure conditions—reflecting the inspection and policy-enforcement demands of gateway appliances. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skyhighsecurity over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2310CRITICAL An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 | Jul 27, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-4400MEDIUM
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, | Sep 13, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-6398MEDIUM An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to | Jul 15, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skyhighsecurity.
Media articles that mention a CVE ID that affects a product developed by Skyhighsecurity — matched by CVE ID, not by vendor name.