Thalesgroup's vulnerability profile centers on a focused set of security and licensing products including authentication clients, key management appliances, and protection installers that serve enterprise and regulated environments. The recurring exposure pattern involves privilege-management and access-control weaknesses alongside path-traversal and dynamic-code-handling issues, reflecting the sensitive operations these products perform around credential storage, license enforcement, and software integrity. Current exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thalesgroup over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32928CRITICAL The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private network | Jun 16, 2021 | 9.8 | 28 | NO | NO |
CVE-2026-6805HIGH Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force att | May 7, 2026 | 7.5 | 27 | NO | NO |
CVE-2023-5993HIGH A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access. | Feb 27, 2024 | 7.8 | 25 | NO | NO |
CVE-2021-42810HIGH A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed. | Jan 19, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-42809HIGH Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | Dec 20, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-28979MEDIUM SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to caus | Jun 16, 2021 | 6.5 | 24 | NO | NO |
CVE-2024-0197HIGH A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
| Feb 27, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-7016HIGH A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. | Feb 27, 2024 | 7.8 | 22 | NO | NO |
CVE-2021-42056MEDIUM Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, t | Jun 24, 2022 | 6.7 | 22 | NO | NO |
CVE-2021-42811MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the unde | Jun 10, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thalesgroup.
Media articles that mention a CVE ID that affects a product developed by Thalesgroup — matched by CVE ID, not by vendor name.