Xcitium develops endpoint detection and response (EDR) technology centered on its OpenEDR product, a security monitoring and incident-response platform deployed across enterprise environments. The vendor's durable signal reflects vulnerability patterns typical of native security software: excessive privilege elevation in agent processes and improper search-path handling that could undermine the isolation properties defenders rely on from endpoint protection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xcitium over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69784HIGH A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redire | Mar 16, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-69783HIGH A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). T | Mar 16, 2026 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xcitium.
Media articles that mention a CVE ID that affects a product developed by Xcitium — matched by CVE ID, not by vendor name.