Nozomi Networks has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 5.4 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Weakness classes
Products
- Guardian 5
Worst active — by depth score
CVE-2026-33389High· 7.5An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provi…41CVE-2026-33388High· 7.4An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges41CVE-2026-33391Medium· 5.4An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges30CVE-2026-33387Medium· 4.6A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter25CVE-2026-33920Low· 3.5A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token19
Nozomi Networks vulnerabilities
CVEs affecting Nozomi Networks, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-33920Low· 3.5A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token
A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenti…
CVE-2026-33391Medium· 5.4An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges
An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can remotely bypass the intended access cont…
CVE-2026-33389High· 7.5An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provi…
An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provi…
CVE-2026-33388High· 7.4An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available ent…
CVE-2026-33387Medium· 4.6A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter
A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload,…