Sage has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.0 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Sage vulnerabilities
CVEs affecting Sage, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-68484Critical· 9.0Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts an…
▾ MidnightSage · Sage AR AutomationEPSS 0.17%via NVD
CVE-2026-67403Critical· 9.0Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API
Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specif…
▾ MidnightSage · Sage AR AutomationEPSS 0.17%via NVD