Telekom's vulnerability profile centers on its cloud storage and productivity service MagentaCloud, with observed weaknesses centered on account-security boundaries including insufficient brute-force protections, time-of-check time-of-use race conditions, and weak password-recovery mechanisms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telekom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69615CRITICAL Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Tele | Mar 10, 2026 | 9.1 | 30 | NO | NO |
CVE-2025-69614CRITICAL Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telek | Mar 10, 2026 | 9.4 | 29 | NO | NO |
CVE-2019-9486HIGH STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a | Apr 30, 2019 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telekom.
Media articles that mention a CVE ID that affects a product developed by Telekom — matched by CVE ID, not by vendor name.