Unisys maintains a focused portfolio of enterprise systems and firmware, including its Stealth security platform, ClearPath MCP mainframe environment, and related data-management and middleware tools, that serve specialized workloads in government and financial sectors. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure remains concentrated within this niche set of products rather than distributed across a broad consumer or commodity install base. The recurring weakness classes—including buffer-boundary violations, input-validation flaws, and improper handling of sensitive information in logs—reflect the systems-level and protocol-parsing demands of mainframe and specialized-infrastructure software. Defenders managing these environments should prioritize Unisys advisories despite their limited volume, as critical flaws in this tier often carry outsized impact on availability and data integrity. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unisys over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39907CRITICAL Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the Rea | Apr 14, 2026 | 10.0 | 35 | NO | NO |
CVE-2026-39906CRITICAL Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 m | Apr 14, 2026 | 10.0 | 34 | NO | NO |
CVE-2021-43394CRITICAL Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not proper | Jan 24, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-32555HIGH Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery at | Sep 13, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-12647HIGH Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting c | May 21, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-18386HIGH Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecified impact when receiving specifically crafted message paylo | Jan 7, 2020 | 8.7 | 27 | NO | NO |
CVE-2009-1628HIGH Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packe | Jun 26, 2009 | 10.0 | 26 | NO | NO |
CVE-2018-8802HIGH SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters. | Mar 26, 2018 | 8.1 | 25 | NO | NO |
CVE-2017-5872HIGH The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows re | Mar 10, 2017 | 7.5 | 25 | NO | NO |
CVE-2002-2179HIGH The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap. | Dec 31, 2002 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unisys.
Media articles that mention a CVE ID that affects a product developed by Unisys — matched by CVE ID, not by vendor name.