Ubisoft's vulnerability footprint is concentrated in its gaming and digital-distribution platform products, particularly the UPlay launcher and select game titles, representing a consumer-focused attack surface rather than enterprise infrastructure. The observed vulnerability patterns center on application-layer weaknesses, including improper input validation and incorrect default permissions that are characteristic of client-facing software. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ubisoft over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14737HIGH Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. | Oct 14, 2019 | 7.8 | 35 | NO | YES |
CVE-2005-0906HIGH Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote att | May 2, 2005 | 7.5 | 30 | NO | YES |
CVE-2018-15832HIGH upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that t | Sep 20, 2018 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ubisoft.
Media articles that mention a CVE ID that affects a product developed by Ubisoft — matched by CVE ID, not by vendor name.