Webroot provides endpoint security and cloud-based threat intelligence products including SecureAnywhere, BrightCloud, and related endpoint agents that serve consumer and small-business markets. Vulnerabilities affecting the vendor skew toward serious outcomes, reaching critical severity across its protection and agent platforms, and recur through weakness classes including type confusion, authorization failures, out-of-bounds reads, race conditions, and resource-exposure flaws that reflect the privileged execution context and multi-threaded demands of endpoint security software. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webroot over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7826CRITICAL Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality M | Oct 3, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-7824CRITICAL Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functi | Oct 3, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-7825CRITICAL Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functi | Oct 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2018-4012HIGH An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlon | Jan 3, 2019 | 8.1 | 26 | NO | NO |
CVE-2018-4015HIGH An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by de | Dec 18, 2018 | 8.1 | 25 | NO | NO |
CVE-2018-16962HIGH Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges. | Sep 12, 2018 | 7.8 | 25 | NO | NO |
CVE-2020-5754CRITICAL Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading | Jun 15, 2020 | 9.1 | 23 | NO | NO |
CVE-2023-29820MEDIUM An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the | May 12, 2023 | 5.5 | 22 | NO | NO |
CVE-2023-29819MEDIUM An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload. | May 12, 2023 | 5.5 | 22 | NO | NO |
CVE-2023-29818MEDIUM An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being st | May 12, 2023 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webroot.
Media articles that mention a CVE ID that affects a product developed by Webroot — matched by CVE ID, not by vendor name.