Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unisys

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 28
30.3
VTI Score
Low

Unisys maintains a focused portfolio of enterprise systems and firmware, including its Stealth security platform, ClearPath MCP mainframe environment, and related data-management and middleware tools, that serve specialized workloads in government and financial sectors. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure remains concentrated within this niche set of products rather than distributed across a broad consumer or commodity install base. The recurring weakness classes—including buffer-boundary violations, input-validation flaws, and improper handling of sensitive information in logs—reflect the systems-level and protocol-parsing demands of mainframe and specialized-infrastructure software. Defenders managing these environments should prioritize Unisys advisories despite their limited volume, as critical flaws in this tier often carry outsized impact on availability and data integrity. Current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Unisys over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Apr 14, 2026
102 days ago

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-39907CRITICAL
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the Rea
Apr 14, 202610.035NONO
CVE-2026-39906CRITICAL
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 m
Apr 14, 202610.034NONO
CVE-2021-43394CRITICAL
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not proper
Jan 24, 20229.830NONO
CVE-2022-32555HIGH
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery at
Sep 13, 20228.827NONO
CVE-2020-12647HIGH
Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting c
May 21, 20208.827NONO
CVE-2019-18386HIGH
Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecified impact when receiving specifically crafted message paylo
Jan 7, 20208.727NONO
CVE-2009-1628HIGH
Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packe
Jun 26, 200910.026NONO
CVE-2018-8802HIGH
SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
Mar 26, 20188.125NONO
CVE-2017-5872HIGH
The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows re
Mar 10, 20177.525NONO
CVE-2002-2179HIGH
The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap.
Dec 31, 20027.825NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
29%
57%
14%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (32.1%)
Network17 (60.7%)
Unknown2 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (67.9%)
High7 (25.0%)
Unknown2 (7.1%)
User Interaction
None24 (85.7%)
Unknown2 (7.1%)
Required2 (7.1%)
Privileges Required
Low8 (28.6%)
High4 (14.3%)
None14 (50.0%)
Unknown2 (7.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unisys.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unisys — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unisys's Products

View all 3 CNAs →

Top CWEs