Yubico develops authentication hardware and software tools—principally the YubiKey line of hardware security keys and supporting management tools such as YubiHSM Shell and PAM modules—that are deployed widely in enterprise identity and access-control environments. The vendor's vulnerability footprint, while modestly sized, clusters around memory-safety and input-validation weaknesses in its credential-management and authentication-protocol implementations, including out-of-bounds reads and writes, improper input validation, and control-flow irregularities. The exposure spans both hardware firmware and host-side software components, reflecting the complexity of cryptographic key handling and secure communication between authentication devices and endpoints. Defenders tracking this vendor should monitor releases for its PAM integrations and YubiHSM management interfaces in particular, as flaws in these attack surfaces can compromise the trust model of the authentication layer. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yubico over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4120CRITICAL Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM con | Nov 26, 2019 | 9.8 | 29 | NO | NO |
CVE-2020-10185HIGH The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate | Mar 5, 2020 | 8.6 | 26 | NO | NO |
CVE-2019-12210HIGH In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This lead | Jun 4, 2019 | 8.1 | 26 | NO | NO |
CVE-2019-12209HIGH Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that | Jun 4, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-9275HIGH In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to i | Apr 4, 2018 | 8.2 | 25 | NO | NO |
CVE-2025-23013HIGH In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support auth | Jan 15, 2025 | 7.3 | 24 | NO | NO |
CVE-2021-43399HIGH The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and som | Dec 8, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-28484HIGH An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of | Apr 14, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-24388HIGH An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the d | Oct 19, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-24387HIGH An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An inval | Oct 19, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yubico.
Media articles that mention a CVE ID that affects a product developed by Yubico — matched by CVE ID, not by vendor name.