VulnSea

Claris has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. Most affected products: FileMaker Server (3), FileMaker Pro (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
Publish → KEV
Last 90 days
4 prev 0

Products

  • FileMaker Server 3
  • FileMaker Pro 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Claris vulnerabilities

CVEs affecting Claris, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-86930None
today

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulne…

SunlitClaris · FileMaker Servervia NVD
CVE-2026-86926None
today

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulne…

SunlitClaris · FileMaker Servervia NVD
CVE-2026-86938None
today

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability…

SunlitClaris · FileMaker Provia NVD
CVE-2026-86934None
today

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing …

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing …

SunlitClaris · FileMaker Servervia NVD
Claris vulnerabilities (CVEs) · VulnSea