Valmet's vulnerability footprint centers on its DNA industrial control and automation platform, which supports critical manufacturing and pulp-and-paper operations. The recurring weaknesses cluster around access control, input validation, and information disclosure—including authentication bypass, OS command injection, path traversal, and error-message leakage—reflecting the command-interface and system-integration surface typical of process-control software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Valmet over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26726HIGH A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: V | Feb 16, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-15577HIGH An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.This issue affects Valmet DNA Web Tools: C2022 and older. | Feb 12, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Valmet.
Media articles that mention a CVE ID that affects a product developed by Valmet — matched by CVE ID, not by vendor name.